StatewardStateward
PlatformPricingComplianceVulnerabilitiesCase studiesDocsBlogAbout
enfr
Book a Demo / ContactGet started free
← All vulnerabilities
MEDIUMSupply chain

CVE-2026-53668

npm · react-router-dom

Summary

React Router: Open redirect leading to XSS

Advisory details

Applications with open redirects could permit attacker crafted links to result in redirects to unexpected external location or XSS vectors.

References

  • https://github.com/advisories/GHSA-jjmj-jmhj-qwj2
  • https://github.com/remix-run/react-router/security/advisories/GHSA-jjmj-jmhj-qwj2
  • https://github.com/remix-run/react-router/pull/14718
  • https://github.com/remix-run/react-router/commit/3a5b5ad0e5cf9918c646509563f5c41a89226ff3
  • https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180
  • https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0
SourceStateward
Severitymedium
CVSS6.9
EPSS0.3% (p20)
Also known asGHSA-jjmj-jmhj-qwj2#react-router-dom
CWECWE-601
Added2026-07-23

Is your project exposed to this? Stateward checks every dependency on every pull request, and flags it only if your code actually reaches it.

Check my repo
Summarize with
ChatGPTClaudePerplexity

Related vulnerabilities

All Supply chain →
  • CRITICALCVE-2026-71428

    unstructured: Server-Side Request Forgery in the URL-based partitioning

  • MEDIUMCVE-2026-55461

    Snipe-IT has an Open Redirect After User Edit

  • MEDIUMCVE-2026-55834

    Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none

  • MEDIUMCVE-2026-54770

    WebOb: Open redirect in Location header normalization via leading C0 control / space characters

  • HIGHCVE-2026-53728

    Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage

  • MEDIUMCVE-2026-55087

    ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header

StatewardStateward

Autonomous cybersecurity for your entire codebase.

A venture of Yggdrasil Digital.

Product

  • Platform
  • What we detect
  • How we protect you
  • Pricing
  • Compliance
  • Vulnerabilities
  • Blog
  • Get started free

Resources

  • Breach breakdowns
  • Merge-induced flaws
  • Docs
  • Sample finding
  • Glossary
  • Compare
  • Threat feed API ↗

Company

  • About
  • Yggdrasil Digital ↗

Legal

  • Legal notice
  • Terms of Use
  • Terms of Sale
  • Privacy
  • Cookies
  • DPA

Connect

  • GitHub ↗
  • X ↗
  • Yggdrasil Digital ↗
  • Threat feed (RSS) ↗
  • hello@stateward.com

Stateward provides automated security analysis and does not guarantee detection of all vulnerabilities. It is designed to support, not replace, sound security practices and human judgement.

© 2026 Stateward. All rights reserved.A Yggdrasil Digital venture