GHSA-jjmj-jmhj-qwj2MediumCVSS 6.9

React Router: Open redirect leading to XSS

Published
July 23, 2026
Last Modified
July 23, 2026

🔗 CVE IDs covered (1)

📋 Description

Applications with open redirects could permit attacker crafted links to result in redirects to unexpected external location or XSS vectors.

🎯 Affected products2

  • npm/react-router-dom:>= 6.30.2, <= 6.30.4
  • npm/react-router:>= 7.9.6, <= 7.12.0

🔗 References (6)