PT-2026-45799 · Unknown · React Router

·

CVE-2026-33244

·

Published

2026-06-02

·

Updated

2026-08-24

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions React Router versions 7.5.1 through 7.13.1
Description When using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP Location header value can permit Cross-Site Scripting (XSS)—a vulnerability where malicious scripts are injected into trusted websites—in the statically generated HTML files if the redirect location originates from an untrusted source. This issue does not affect applications utilizing Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>).
Recommendations Update to version 7.13.2.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33244
GHSA-F22V-GFQF-P8F3
SUSE-SU-2026:3713-1
SUSE-SU-2026:3714-1

Affected Products

React Router