Summary
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
Advisory details
This is a follow up to CVE-2025-68470. React Router was alerted to certain scenarios in which the fix there was incomplete so there still existed some scenarios where attacker supplied paths passed to navigation mechanisms could result in unexpected external navigations.
References
- https://github.com/advisories/GHSA-wrjc-x8rr-h8h6
- https://github.com/remix-run/react-router/security/advisories/GHSA-wrjc-x8rr-h8h6
- https://github.com/remix-run/react-router/pull/15176
- https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180
- https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0
- http://github.com/remix-run/react-router/pull/15176
Related vulnerabilities
All Supply chain →- CRITICALCVE-2026-71428
unstructured: Server-Side Request Forgery in the URL-based partitioning
- MEDIUMCVE-2026-55461
Snipe-IT has an Open Redirect After User Edit
- MEDIUMCVE-2026-55834
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none
- MEDIUMCVE-2026-54770
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
- HIGHCVE-2026-53728
Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage
- MEDIUMCVE-2026-55087
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header