CVE-2026-53668: CWE-601: URL Redirection to Untrusted Site ('Open Redirect') in remix-run react-router
React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site or that exploits an XSS vector.This issue has been fixed in version 7.13.0.
AI Analysis
Technical Summary
CVE-2026-53668 describes an open redirect vulnerability (CWE-601) in the remix-run react-router library affecting versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0. This vulnerability allows attackers to redirect users to untrusted external sites or exploit an XSS vector by crafting malicious links. The vulnerability has a CVSS 3.1 score of 6.9, indicating a medium severity with network attack vector, high complexity, no privileges required, user interaction required, scope changed, high confidentiality impact, low integrity impact, and no availability impact. The issue is resolved in version 7.13.0.
Potential Impact
Exploitation of this vulnerability can lead to users being redirected to malicious external sites or exposure to cross-site scripting attacks, potentially compromising user confidentiality. The integrity impact is low, and availability is not affected. No known exploits are reported in the wild.
Mitigation Recommendations
Upgrade react-router to version 7.13.0 or later, where this vulnerability has been fixed. Patch status is confirmed by the vendor stating the fix in 7.13.0. No other official remediation or temporary fixes are indicated.
CVE-2026-53668: CWE-601: URL Redirection to Untrusted Site ('Open Redirect') in remix-run react-router
Description
React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site or that exploits an XSS vector.This issue has been fixed in version 7.13.0.
CVSS v3.1
Score 6.9medium
Affected software
remix-run
react-router
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-53668 describes an open redirect vulnerability (CWE-601) in the remix-run react-router library affecting versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0. This vulnerability allows attackers to redirect users to untrusted external sites or exploit an XSS vector by crafting malicious links. The vulnerability has a CVSS 3.1 score of 6.9, indicating a medium severity with network attack vector, high complexity, no privileges required, user interaction required, scope changed, high confidentiality impact, low integrity impact, and no availability impact. The issue is resolved in version 7.13.0.
Potential Impact
Exploitation of this vulnerability can lead to users being redirected to malicious external sites or exposure to cross-site scripting attacks, potentially compromising user confidentiality. The integrity impact is low, and availability is not affected. No known exploits are reported in the wild.
Mitigation Recommendations
Upgrade react-router to version 7.13.0 or later, where this vulnerability has been fixed. Patch status is confirmed by the vendor stating the fix in 7.13.0. No other official remediation or temporary fixes are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-09T20:50:36.877Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a67d32d9c2644c7f8e4ddae
Added to database: 07/27/2026, 21:52:45 UTC
Last enriched: 07/29/2026, 23:55:10 UTC
Last updated: 09/10/2026, 20:01:51 UTC
Views: 118
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.