PT-2026-2137 · Unknown+1 · @Remix-Run/Router+2

Oceandust

·

Published

2026-01-08

·

Updated

2026-04-21

·

CVE-2026-22029

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions React Router versions 7.0.0 through 7.11.0 @remix-run/router versions prior to 1.23.2
Description React Router, a router for React, is susceptible to open redirect issues. Specifically, Single Page Applications (SPAs) using React Router (and Remix v1/v2) in Framework Mode, Data Mode, or the unstable RSC modes may experience unsafe URLs leading to unintended javascript execution on the client when handling redirects originating from loaders or actions. This is only a concern when redirect paths are created from untrusted content or via an open redirect. The issue does not affect applications using Declarative Mode ().
Recommendations React Router versions 7.0.0 through 7.11.0: Update to version 7.12.0 or later. @remix-run/router versions prior to 1.23.2: Update to version 1.23.2 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-22029
GHSA-2W69-QVJG-HVJX
OPENSUSE-SU-2026:10069-1
RHSA-2026:3958
RHSA-2026:3959

Affected Products

@Remix-Run/Router
Confluence
React Router