Summary
React Router: Open redirect leading to XSS
Advisory details
Applications with open redirects could permit attacker crafted links to result in redirects to unexpected external location or XSS vectors.
References
- https://github.com/advisories/GHSA-jjmj-jmhj-qwj2
- https://github.com/remix-run/react-router/security/advisories/GHSA-jjmj-jmhj-qwj2
- https://github.com/remix-run/react-router/pull/14718
- https://github.com/remix-run/react-router/commit/3a5b5ad0e5cf9918c646509563f5c41a89226ff3
- https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180
- https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0
Related vulnerabilities
All Supply chain →- CRITICALCVE-2026-71428
unstructured: Server-Side Request Forgery in the URL-based partitioning
- MEDIUMCVE-2026-55461
Snipe-IT has an Open Redirect After User Edit
- MEDIUMCVE-2026-55834
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none
- MEDIUMCVE-2026-54770
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
- HIGHCVE-2026-53728
Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage
- MEDIUMCVE-2026-55087
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header