HIGH🇵🇱 Wersja polska

CVE-2026-33245

CVSS 8.0v3.1pub. 2026-06-02upd. 2026-07-22

React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Shopify React Router

    APP
    Shopify
    7.7.0 – 7.13.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2026-55685HIGH8.7PL ✓same product

React Router: Atak DoS na endpoint manifest — nadmierne obciążenie serwera

CVE-2026-42342HIGH7.5same product

React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 throu...

CVE-2026-34077HIGH7.5same product

React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React...

CVE-2026-42211HIGH8.1same product

React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination...

CVE-2026-21884HIGH8.2same product

React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 throug...