Medium severity6.9OSV Advisory· Published Jul 27, 2026· Updated Aug 3, 2026
CVE-2026-53668
CVE-2026-53668
Description
React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site or that exploits an XSS vector.This issue has been fixed in version 7.13.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
66.30.2 - 6.30.4, 7.9.6 - 7.12.0+ 1 more
- (no CPE)range: 6.30.2 - 6.30.4, 7.9.6 - 7.12.0
- (no CPE)
- osv-coords3 versionspkg:apk/chainguard/keycloak-26.7pkg:apk/chainguard/librechatpkg:apk/chainguard/keycloak-26.7-iamguarded-compat
< 26.7.3-r0+ 2 more
- (no CPE)range: < 26.7.3-r0
- (no CPE)range: < 0.8.7-r7
- (no CPE)range: < 26.7.3-r0
Patches
Vulnerability mechanics
References
9- github.com/remix-run/react-router/commit/3a5b5ad0e5cf9918c646509563f5c41a89226ff3nvdPatch
- github.com/remix-run/react-router/pull/14718nvdIssue TrackingPatch
- github.com/advisories/GHSA-jjmj-jmhj-qwj2ghsaADVISORY
- github.com/remix-run/react-router/security/advisories/GHSA-jjmj-jmhj-qwj2nvdThird Party Advisory
- github.com/remix-run/react-router/blob/main/CHANGELOG.mdnvdRelease Notes
- github.com/remix-run/react-router/releases/tag/[email protected]nvdRelease Notes
- github.com/remix-run/react-router/blob/v6/CHANGELOG.mdghsa
- github.com/remix-run/react-router/releases/tag/[email protected]ghsa
- nvd.nist.gov/vuln/detail/CVE-2026-53668ghsa
News mentions
1- React Router: Five Moderate Vulnerabilities Including Open Redirects and XSS Disclosed TogetherVypr Intelligence · Jul 27, 2026