CVE-2026-53668

React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site or that exploits an XSS vector.This issue has been fixed in version 7.13.0.
Configurations

No configuration.

History

27 Jul 2026, 22:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-27 22:17

Updated : 2026-07-28 16:11


NVD link : CVE-2026-53668

Mitre link : CVE-2026-53668

CVE.ORG link : CVE-2026-53668


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')