Executive brief
React Router is a popular library used to manage navigation and URL routing in React-based web applications. A vulnerability exists where applications using specific versions of this library may allow attackers to redirect users to malicious external websites or execute unauthorized scripts in the user's browser. This could lead to the theft of sensitive information, such as login credentials or session tokens, if a user clicks on a specially crafted link.
Technical details
A vulnerability in React Router's path normalization and navigation logic, specifically within the `useNavigate` hook and `resolvePath` functions, allows for open redirects that can be escalated to Cross-Site Scripting (XSS). The flaw stems from improper handling of double slashes and colons in navigation paths, which can be manipulated to bypass intended routing constraints. An unauthenticated remote attacker can exploit this by inducing a user to click a malicious link. If the application is configured to allow redirects based on user-supplied input, the attacker can redirect the victim to an arbitrary external domain or execute JavaScript within the context of the vulnerable application. The issue has been addressed in version 7.13.0 by improving path normalization logic.
Affected products
- remix-run react-router >= 6.30.2, <= 6.30.4; >= 7.9.6, < 7.13.0
- remix-run react-router-dom >= 6.30.2, <= 6.30.4
Timeline
- 2026-01-09: other: Pull request submitted to fix double slash normalization
- 2026-01-16: patched: Fix merged into development branch
- 2026-07-22: advisory: GitHub Security Advisory published
- 2026-07-27: disclosed: CVE published to NVD
References
- https://github.com/remix-run/react-router/blob/main/CHANGELOG.md
- https://github.com/remix-run/react-router/commit/3a5b5ad0e5cf9918c646509563f5c41a89226ff3
- https://github.com/remix-run/react-router/pull/14718
- https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0
- https://github.com/remix-run/react-router/security/advisories/GHSA-jjmj-jmhj-qwj2