Intel

AIKIDO-2025-10199

@payloadcms/next is vulnerable to Open Redirect

Open Redirect Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 2, 2025

60

Medium Risk

This Affects:

JS@payloadcms/next
3.31.0 - 3.31.0
Fixed in 3.32.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to an open redirect in the getSafeRedirect method due to improper input validation. The method fails to correctly escape, normalize, or encode URLs before processing redirects, allowing an attacker to craft a malicious URL that redirects users to phishing or malicious sites. This can deceive users into visiting unintended domains under the guise of a legitimate link.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@payloadcms/next is vulnerable to Open Redirect in versions 3.31.0 - 3.31.0.

How to fix this

Upgrade the @payloadcms/next library to the patch version.