PT-2026-2137 · Unknown+1 · @Remix-Run/Router+2
Oceandust
·
Published
2026-01-08
·
Updated
2026-04-21
·
CVE-2026-22029
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
React Router versions 7.0.0 through 7.11.0
@remix-run/router versions prior to 1.23.2
Description
React Router, a router for React, is susceptible to open redirect issues. Specifically, Single Page Applications (SPAs) using React Router (and Remix v1/v2) in Framework Mode, Data Mode, or the unstable RSC modes may experience unsafe URLs leading to unintended javascript execution on the client when handling redirects originating from loaders or actions. This is only a concern when redirect paths are created from untrusted content or via an open redirect. The issue does not affect applications using Declarative Mode ().
Recommendations
React Router versions 7.0.0 through 7.11.0: Update to version 7.12.0 or later.
@remix-run/router versions prior to 1.23.2: Update to version 1.23.2 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Remix-Run/Router
Confluence
React Router