PT-2026-46087 · Npm · React Router

Published

2026-06-03

·

Updated

2026-06-03

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
When using React Router v7's unstable RSC APIs, there exists a potential client-side XSS issue in the RSC redirect handling if redirects are coming from untrusted sources
[!NOTE] This only impacts your application if you are using the unstable RSC APIs in React Router.

Fix

XSS

Weakness Enumeration

Related Identifiers

GHSA-8646-J5J9-6R62

Affected Products

React Router