PT-2026-64214 · Unknown · React Router
CVE-2026-53668
·
Published
2026-07-23
·
Updated
2026-08-03
CVSS v3.1
6.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
React Router versions 6.30.2 through 6.30.4
React Router versions 7.9.6 through 7.12.0
Description
Applications that allow open redirects are susceptible to Cross-Site Scripting (XSS), a technique where malicious scripts are injected into trusted websites. An attacker can craft a malicious link that redirects users to an unexpected external site or leverages an XSS vector.
Recommendations
Update React Router versions 6.30.2 through 6.30.4 to version 7.13.0.
Update React Router versions 7.9.6 through 7.12.0 to version 7.13.0.
Exploit
Fix
Open Redirect
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
React Router