Medium severity6.1OSV Advisory· Published Jul 27, 2026· Updated Aug 3, 2026
CVE-2026-53669
CVE-2026-53669
Description
React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in and useNavigate. This issue is a follow up to CVE-2025-68470 and has been fixed in version 7.18.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
react-routernpm | >= 6.0.0, < 7.18.0 | 7.18.0 |
Affected products
126.0.0 - 7.17.0+ 1 more
- (no CPE)range: 6.0.0 - 7.17.0
- (no CPE)
- osv-coords9 versionspkg:apk/chainguard/keycloak-26.5-iamguarded-compatpkg:apk/chainguard/librechatpkg:apk/chainguard/keycloak-26.7-iamguarded-compatpkg:apk/chainguard/keycloak-26.7pkg:apk/chainguard/vitess-24pkg:apk/wolfi/keycloak-26.5pkg:apk/wolfi/keycloak-26.5-iamguarded-compatpkg:apk/wolfi/vitess-24pkg:apk/chainguard/keycloak-26.5
< 26.5.7-r3+ 8 more
- (no CPE)range: < 26.5.7-r3
- (no CPE)range: < 0.8.7-r7
- (no CPE)range: < 26.7.2-r1
- (no CPE)range: < 26.7.2-r1
- (no CPE)range: < 24.0.2-r7
- (no CPE)range: < 26.5.7-r3
- (no CPE)range: < 26.5.7-r3
- (no CPE)range: < 24.0.2-r7
- (no CPE)range: < 26.5.7-r3
Patches
Vulnerability mechanics
References
6- github.com/remix-run/react-router/pull/15176nvdIssue TrackingPatchWEB
- github.com/remix-run/react-router/pull/15176nvdIssue TrackingPatchWEB
- github.com/advisories/GHSA-wrjc-x8rr-h8h6ghsaADVISORY
- github.com/remix-run/react-router/security/advisories/GHSA-wrjc-x8rr-h8h6nvdThird Party AdvisoryWEB
- github.com/remix-run/react-router/blob/main/CHANGELOG.mdnvdRelease NotesWEB
- github.com/remix-run/react-router/releases/tag/[email protected]nvdRelease NotesWEB
News mentions
1- React Router: Five Moderate Vulnerabilities Including Open Redirects and XSS Disclosed TogetherVypr Intelligence · Jul 27, 2026