Executive brief
React Router, a popular library for managing navigation in web applications, contains a security flaw in its experimental React Server Components (RSC) features. If an application uses these specific experimental tools and processes navigation requests from untrusted sources, an attacker could execute malicious scripts in a user's browser. This could lead to the theft of sensitive session information or unauthorized actions performed on behalf of the user.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in React Router v7 when utilizing unstable React Server Components (RSC) APIs. The vulnerability is rooted in the RSC redirect handling logic, which fails to properly neutralize 'javascript:' URI schemes when processing redirect targets from untrusted sources. An attacker can exploit this by providing a malicious redirect URL, leading to client-side script execution in the context of the victim's browser session. This requires the application to be using the experimental RSC features and typically involves user interaction to trigger the malicious redirect. The issue is addressed in version 7.13.2.
Affected products
- remix-run react-router >= 7.7.0, < 7.13.2
Timeline
- 2026-06-02: disclosed
- 2026-06-03: advisory
- 2026-06-03: patched: Fixed in version 7.13.2