{"id":"CVE-2026-53668","aliases":["GHSA-jjmj-jmhj-qwj2"],"title":"React Router: Open redirect leading to XSS","summary":"React Router: Open redirect leading to XSS","severity":"medium","cvss":6.9,"cwe":["CWE-79","CWE-601"],"vendor":"react-router","product":"react-router","ecosystem":"npm","affected":["react-router >= 7.9.6, <= 7.12.0","react-router-dom >= 6.30.2, <= 6.30.5"],"patched":["react-router 7.13.0","react-router-dom 6.30.6"],"published":"2026-07-23","updated":"2026-09-08","sourceUpdated":"2026-09-08T15:09:29Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-jjmj-jmhj-qwj2","references":[{"url":"https://github.com/remix-run/react-router/security/advisories/GHSA-jjmj-jmhj-qwj2"},{"url":"https://github.com/remix-run/react-router/pull/14718"},{"url":"https://github.com/remix-run/react-router/commit/3a5b5ad0e5cf9918c646509563f5c41a89226ff3"},{"url":"https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180"},{"url":"https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53668"},{"url":"https://github.com/remix-run/react-router/blob/v6/CHANGELOG.md#v6306"},{"url":"https://github.com/remix-run/react-router/releases/tag/react-router@6.30.6"},{"url":"https://github.com/advisories/GHSA-jjmj-jmhj-qwj2"}],"tags":["ghsa","npm"],"epss":0.0028,"epssPercentile":0.20707,"ingestedAt":"2026-07-23T20:19:19.525Z","slug":"CVE-2026-53668","body":"## Overview\n\nApplications with open redirects could permit attacker crafted links to result in redirects to unexpected external location or XSS vectors.\n\n## Affected packages\n\n- `react-router >= 7.9.6, <= 7.12.0`\n- `react-router-dom >= 6.30.2, <= 6.30.5`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `react-router 7.13.0`\n- `react-router-dom 6.30.6`","depth":"sunlit","depthScore":38,"depthScoreParts":{"impact":38,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}