PT-2026-45799 · Unknown · React Router
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
React Router versions 7.5.1 through 7.13.1
Description
When using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP
Location header value can permit Cross-Site Scripting (XSS)—a vulnerability where malicious scripts are injected into trusted websites—in the statically generated HTML files if the redirect location originates from an untrusted source. This issue does not affect applications utilizing Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>).Recommendations
Update to version 7.13.2.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
React Router