Executive brief
React Router, a popular library for managing navigation in React web applications, is vulnerable to an open redirect flaw. An attacker can craft a malicious link using backslashes that, when clicked by a user, redirects them to an external, potentially harmful website instead of the intended page within the application. This can be used in phishing campaigns to trick users into providing credentials or downloading malware on a site that appears legitimate.
Technical details
React Router versions 6.0.0 through 7.17.0 are vulnerable to an open redirect (CWE-601). This issue is a bypass of the fix for CVE-2025-68470. The vulnerability exists because the URL normalization logic in the <Link> component and useNavigate hook fails to properly sanitize backslashes in attacker-supplied paths. An unauthenticated remote attacker can exploit this by inducing a user to click a specially crafted link, leading to an unexpected external navigation. The issue has been addressed in version 7.18.0 by consolidating and improving the URL normalization logic.
Affected products
- remix-run react-router >= 6.0.0, < 7.18.0
Timeline
- 2026-06-11: patched: Fix merged into main branch via PR 15176
- 2026-07-22: advisory: GitHub Security Advisory GHSA-wrjc-x8rr-h8h6 published
- 2026-07-27: disclosed: CVE-2026-53669 published to NVD
References
- http://github.com/remix-run/react-router/pull/15176
- https://github.com/remix-run/react-router/blob/main/CHANGELOG.md
- https://github.com/remix-run/react-router/pull/15176
- https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0
- https://github.com/remix-run/react-router/security/advisories/GHSA-wrjc-x8rr-h8h6