Skip to content

🔒 CVE-2026-22029 - Security Vulnerability #2345

@github-actions

Description

@github-actions

🚨 Security Vulnerability: CVE-2026-22029

Severity: HIGH
CVSS Score: N/A

Description

React Router vulnerable to XSS via Open Redirects

React Router is a router for React. In @remix-run/router version prior to 1.23.2. and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if you are creating redirect paths from untrusted content or via an open redirect. There is no impact if Declarative Mode () is being used. This issue has been patched in @remix-run/router version 1.23.2 and react-router version 7.12.0.

Affected Package(s)

Package Installed Version Fixed Version
@remix-run/router 1.23.0 1.23.2

References

Remediation

Update @remix-run/router from version 1.23.0 to 1.23.2


Auto-generated by Trivy vulnerability scanner

Metadata

Metadata

Assignees

No one assigned

    Labels

    help wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.kind/bugCategorizes issue or PR as related to a bug.securityvulnerability

    Type

    No type

    Projects

    Status

    In Progress

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions