Junglewise Threat Intelligence

CVE-2026-22029: React Router XSS via unsafe SPA navigation redirects

CVE-2026-22029 · Severity: high · CVSS 8 · Published 2026-01-10

Technologies: Shopify Remix-Run\. Vendors: Shopify, Remix, npm.

Executive brief

React Router is a popular JavaScript library for building single-page applications with client-side navigation. A vulnerability in specific routing modes allows attackers to inject malicious JavaScript code when developers construct redirect URLs from untrusted sources or open redirect scenarios. This could lead to session hijacking, credential theft, or malware distribution to users of affected applications.

Technical details

React Router and Remix v1/v2 suffer from a Cross-Site Scripting (CWE-79) vulnerability in Framework Mode, Data Mode, and unstable RSC modes when handling open navigation redirects originating from loaders or actions. The root cause is insufficient sanitization of redirect paths derived from untrusted content or open redirect vulnerabilities. An attacker can craft a malicious redirect URL containing JavaScript (e.g., `javascript:alert()` or data URIs) that executes in the user's browser when the redirect is processed. The vulnerability requires user interaction (navigation trigger) and network access to the application. Declarative Mode applications using `<BrowserRouter>` are not affected. Patches are available: react-router 7.12.0+ and @remix-run/router 1.23.2+.

Affected products

  • Remix react-router 7.0.0 to 7.11.0
  • Remix @remix-run/router < 1.23.2

Timeline

  • 2026-01-08: disclosed: Advisory published
  • 2026-01-08: patched: react-router 7.12.0 and @remix-run/router 1.23.2 patched versions released

References

Related threats