CVE-2026-53668: React Router: Open redirect leading to XSS
Applications with open redirects could permit attacker crafted links to result in redirects to unexpected external location or XSS vectors.
References
- github.com/advisories/GHSA-jjmj-jmhj-qwj2
- github.com/remix-run/react-router/blob/main/CHANGELOG.md
- github.com/remix-run/react-router/commit/3a5b5ad0e5cf9918c646509563f5c41a89226ff3
- github.com/remix-run/react-router/pull/14718
- github.com/remix-run/react-router/releases/tag/react-router@7.18.0
- github.com/remix-run/react-router/security/advisories/GHSA-jjmj-jmhj-qwj2
- nvd.nist.gov/vuln/detail/CVE-2026-53668
Code Behaviors & Features
Detect and mitigate CVE-2026-53668 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →