CVE-2026-40181

React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigger an open redirect to an external domain due to path values starting with // being reinterpreted as protocol-relative URLs. The level of impact depends on the validation done by the application prior to returning the redirect. This does not impact applications using Declarative Mode (<BrowserRouter>). This is patched in versions 7.14.1 and 6.30.4.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*
cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*

History

04 Jun 2026, 18:46

Type Values Removed Values Added
CPE cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*
First Time Shopify
Shopify react-router
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://github.com/remix-run/react-router/security/advisories/GHSA-2j2x-hqr9-3h42 - () https://github.com/remix-run/react-router/security/advisories/GHSA-2j2x-hqr9-3h42 - Vendor Advisory

02 Jun 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-02 20:16

Updated : 2026-06-04 18:46


NVD link : CVE-2026-40181

Mitre link : CVE-2026-40181

CVE.ORG link : CVE-2026-40181


JSON object : View

Products Affected

shopify

  • react-router
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')