CVE-2026-53668

MEDIUM

React Router - Open Redirect to Cross-Site Scripting

Title source: manual
STIX 2.1

Description

React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site or that exploits an XSS vector.This issue has been fixed in version 7.13.0.

Scores

CVSS v3 6.9
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N

Details

CWE
CWE-601 CWE-79
Status published
Products (2)
remix-run/react-router >= 6.30.2, <= 6.30.4
remix-run/react-router >= 7.9.6, < 7.13.0
Published Jul 27, 2026
Tracked Since Jul 28, 2026