GHSA-jjmj-jmhj-qwj2MediumCVSS 6.9
React Router: Open redirect leading to XSS
🔗 CVE IDs covered (1)
📋 Description
Applications with open redirects could permit attacker crafted links to result in redirects to unexpected external location or XSS vectors.
🎯 Affected products2
- npm/react-router:>= 7.9.6, <= 7.12.0
- npm/react-router-dom:>= 6.30.2, <= 6.30.5
🔗 References (9)
- https://github.com/remix-run/react-router/security/advisories/GHSA-jjmj-jmhj-qwj2
- https://github.com/remix-run/react-router/pull/14718
- https://github.com/remix-run/react-router/commit/3a5b5ad0e5cf9918c646509563f5c41a89226ff3
- https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180
- https://github.com/remix-run/react-router/releases/tag/[email protected]
- https://nvd.nist.gov/vuln/detail/CVE-2026-53668
- https://github.com/remix-run/react-router/blob/v6/CHANGELOG.md#v6306
- https://github.com/remix-run/react-router/releases/tag/[email protected]
- https://github.com/advisories/GHSA-jjmj-jmhj-qwj2