CVE-2026-105846: CVE-2026-105846: Open Redirect in Payload CMS via Control Character Bypass
CVE-2026-105846: Open Redirect in Payload CMS via Control Character Bypass Vulnerability ID: CVE-2026-105846 CVSS Score: 6.1 Published: 2026-10-06 An open redirect vulnerability exists in Payload CMS within its Next
CVE-2026-105846: Open Redirect in Payload CMS via Control Character Bypass
Vulnerability ID: CVE-2026-105846
CVSS Score: 6.1
Published: 2026-10-06
An open redirect vulnerability exists in Payload CMS within its Next.js-based authentication routing components. The sanitization utility fails to properly account for control characters and ambiguous encodings, allowing unauthenticated attackers to redirect users to external malicious domains after successful authentication.
TL;DR
Payload CMS fails to properly validate the redirect parameter on login and registration pages, enabling attackers to execute open redirects by injecting control characters into the path.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-601
- Attack Vector: Network (AV:N)
- CVSS Score: 6.1 (Medium)
- EPSS Score: Not available
- Exploit Status: Proof-of-Concept
- KEV Status: Not Listed
Affected Systems
- Payload CMS (payload)
- Payload CMS Next.js integration (@payloadcms/next)
-
payload: >= 3.40.0, < 3.88.0 (Fixed in:
3.88.0) -
payload: >= 4.0.0-canary.0, < 4.0.0-canary.27 (Fixed in:
4.0.0-canary.27) -
@payloadcms/next: >= 3.31.0, < 3.88.0 (Fixed in:
3.88.0) -
@payloadcms/next: >= 4.0.0-canary.0, < 4.0.0-canary.27 (Fixed in:
4.0.0-canary.27)
Code Analysis
Commit: a742140
fix: safe redirect validation improvements for handling control characters and ambiguous encodings
Mitigation Strategies
- Upgrade Payload CMS dependencies to versions that employ the WHATWG URL API validation framework.
- Deploy Web Application Firewall rules to detect and drop authentication requests containing control characters in query parameters.
- Enforce strict Content Security Policy (CSP) headers to restrict form submissions and navigation destinations.
Remediation Steps:
- Identify all projects running Payload CMS or @payloadcms/next.
- Execute the package manager update command to upgrade to version 3.88.0 or 4.0.0-canary.27.
- Verify the update by testing redirect parameters with injected control characters to ensure fallback handling.
- Audit logs for prior requests containing %09, %0a, or %0d sequences on login routes.
References
- GitHub Security Advisory GHSA-w84c-53h3-mc2g
- NVD CVE-2026-105846 Portal
- Official Release Announcement (v3.88.0)
Read the full report for CVE-2026-105846 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.