MEDIUM 6.9 npm
React Router: Open redirect leading to XSS
GHSA-jjmj-jmhj-qwj2 · CVE-2026-53668
Published · Modified
Description
Applications with open redirects could permit attacker crafted links to result in redirects to unexpected external location or XSS vectors.
References
- WEB https://github.com/remix-run/react-router/security/advisories/GHSA-jjmj-jmhj-qwj2
- WEB https://github.com/remix-run/react-router/pull/14718
- WEB https://github.com/remix-run/react-router/commit/3a5b5ad0e5cf9918c646509563f5c41a89226ff3
- PACKAGE https://github.com/remix-run/react-router
- WEB https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180
- WEB https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0
Ready to move
Start Securing
Free, no credit card | First findings in minutes