---
id: CVE-2026-105846
title: Payload is a free and open source headless content management system
summary: >-
  Payload is a free and open source headless content management system. In
  versions from 3.40.0 before 3.88.0 and canary versions before 4.0.0-canary.27,
  an attacker can craft a redirect URL parameter that sends a guest user to an
  untruste…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-601
vendor: payloadcms
product: payload
affected:
  - 'payload >= 3.40.0, < 3.88.0'
  - 'payload >= 4.0.0-canary.0, < 4.0.0-canary.27'
  - 'next >= 3.31.0, < 3.88.0'
  - 'next >= 4.0.0-canary.0, < 4.0.0-canary.27'
patched:
  - payload 3.88.0
  - payload 4.0.0-canary.27
  - '@payloadcms/next 3.88.0'
  - '@payloadcms/next 4.0.0-canary.27'
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T18:16:48.137'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105846'
references:
  - url: >-
      https://github.com/payloadcms/payload/commit/a742140ab4fca3160f7f83e9e7d996552ffc3b5a
    label: security-advisories@github.com
  - url: 'https://github.com/payloadcms/payload/releases/tag/v3.88.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/payloadcms/payload/security/advisories/GHSA-w84c-53h3-mc2g
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-w84c-53h3-mc2g'
tags:
  - nvd
  - cve.org
  - ghsa
  - npm
aliases:
  - GHSA-w84c-53h3-mc2g
ecosystem: npm
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-06T17:34:11.494178Z'
ingestedAt: '2026-10-06T17:09:22.185Z'
---

## Overview

Payload is a free and open source headless content management system. In versions from 3.40.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an attacker can craft a redirect URL parameter that sends a guest user to an untrusted destination after the authentication flow completes. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-105846)

Affected packages:

- `payload >= 3.40.0, < 3.88.0`
- `payload >= 4.0.0-canary.0, < 4.0.0-canary.27`
- `@payloadcms/next >= 3.31.0, < 3.88.0`
- `@payloadcms/next >= 4.0.0-canary.0, < 4.0.0-canary.27`

Patched in:

- `payload 3.88.0`
- `payload 4.0.0-canary.27`
- `@payloadcms/next 3.88.0`
- `@payloadcms/next 4.0.0-canary.27`

Source: https://github.com/advisories/GHSA-w84c-53h3-mc2g
