Executive brief
React Router is a popular JavaScript library for building single-page applications with client-side navigation. A vulnerability in specific routing modes allows attackers to inject malicious JavaScript code when developers construct redirect URLs from untrusted sources or open redirect scenarios. This could lead to session hijacking, credential theft, or malware distribution to users of affected applications.
Technical details
React Router and Remix v1/v2 suffer from a Cross-Site Scripting (CWE-79) vulnerability in Framework Mode, Data Mode, and unstable RSC modes when handling open navigation redirects originating from loaders or actions. The root cause is insufficient sanitization of redirect paths derived from untrusted content or open redirect vulnerabilities. An attacker can craft a malicious redirect URL containing JavaScript (e.g., `javascript:alert()` or data URIs) that executes in the user's browser when the redirect is processed. The vulnerability requires user interaction (navigation trigger) and network access to the application. Declarative Mode applications using `<BrowserRouter>` are not affected. Patches are available: react-router 7.12.0+ and @remix-run/router 1.23.2+.
Affected products
- Remix react-router 7.0.0 to 7.11.0
- Remix @remix-run/router < 1.23.2
Timeline
- 2026-01-08: disclosed: Advisory published
- 2026-01-08: patched: react-router 7.12.0 and @remix-run/router 1.23.2 patched versions released