Junglewise Threat Intelligence

CVE-2026-33245: React Router XSS in unstable RSC redirect handling

CVE-2026-33245 · Severity: high · CVSS 8 · Published 2026-06-02

Technologies: Remix-Run React Router.

Executive brief

React Router, a popular library for managing navigation in web applications, contains a security flaw in its experimental React Server Components (RSC) features. If an application uses these specific experimental tools and processes navigation requests from untrusted sources, an attacker could execute malicious scripts in a user's browser. This could lead to the theft of sensitive session information or unauthorized actions performed on behalf of the user.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in React Router v7 when utilizing unstable React Server Components (RSC) APIs. The vulnerability is rooted in the RSC redirect handling logic, which fails to properly neutralize 'javascript:' URI schemes when processing redirect targets from untrusted sources. An attacker can exploit this by providing a malicious redirect URL, leading to client-side script execution in the context of the victim's browser session. This requires the application to be using the experimental RSC features and typically involves user interaction to trigger the malicious redirect. The issue is addressed in version 7.13.2.

Affected products

  • remix-run react-router >= 7.7.0, < 7.13.2

Timeline

  • 2026-06-02: disclosed
  • 2026-06-03: advisory
  • 2026-06-03: patched: Fixed in version 7.13.2

References