CVE-2026-53669Medium▾ SunlitReact Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 28.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.5%
This is a follow up to CVE-2025-68470. React Router was alerted to certain scenarios in which the fix there was incomplete so there still existed some scenarios where attacker supplied paths passed to navigation mechanisms could result in unexpected external navigations.
react-router >= 6.0.0, < 7.18.0Upgrade to a patched release:
react-router 7.18.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53668Medium· 6.9React Router: Open redirect leading to XSS
CVE-2026-53666Medium· 6.1React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
CVE-2026-53667Medium· 6.9React Router: RSCErrorHandler Missing Protocol Validation (XSS)
CVE-2026-33244Medium· 5.4React Router has stored XSS via unescaped Location header in prerendered redirect HTML
GHSA-qwww-vcr4-c8h2HighReact Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
CVE-2026-53663Low· 3.1React Router: Potential CSRF via PUT/PATCH/DELETE document requests