Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Yuito-It

#46981of 53,632
5.4Total CVSS
Vulnerabilities · 1
PT-2026-45799
5.4
2026-06-02
Unknown · React Router · CVE-2026-33244
**Name of the Vulnerable Software and Affected Versions** React Router versions 7.5.1 through 7.13.1 **Description** When using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header value can permit Cross-Site Scripting (XSS)—a vulnerability where malicious scripts are injected into trusted websites—in the statically generated HTML files if the redirect location originates from an untrusted source. This issue does not affect applications utilizing Declarative Mode (`<BrowserRouter>`) or Data Mode (`createBrowserRouter/<RouterProvider>`). **Recommendations** Update to version 7.13.2.