Impact
React Router versions 6.30.2–6.30.4 and 7.9.6–7.12.0 contain an open‑redirect flaw that enables attackers to inject and execute arbitrary script code in a user’s browser. Attackers can craft a malicious URL that redirects users to an unintended external site or carries an XSS payload, potentially stealing session cookies, defacing the interface, or redirecting to a phishing page.
Affected Systems
The vulnerable product is Remix Run’s React Router. Any application that uses the affected version ranges listed above and permits open redirects is impacted.
Risk and Exploitability
The CVSS score is 6.9, indicating high severity. The EPSS score is 0.00335 (<1%), and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user to click a crafted link, so the attack vector is user interaction; however, because the redirect can load arbitrary domains, phishing or cross‑site scripting attacks are possible.
OpenCVE Enrichment
Github GHSA