CVE-2026-33245

Source
https://cve.org/CVERecord?id=CVE-2026-33245
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-33245.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-33245
Aliases
Published
2026-06-02T17:14:50.377Z
Modified
2026-06-18T03:57:00.776018766Z
Severity
  • 8.0 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N CVSS Calculator
Summary
React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets
Details

React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33245.json",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/remix-run/react-router

Affected ranges

Type
GIT
Repo
https://github.com/remix-run/react-router
Events
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "extracted_events": [
        {
            "introduced": "7.7.0"
        },
        {
            "fixed": "7.13.2"
        },
        {
            "introduced": "7.7.0"
        },
        {
            "fixed": "7.13.2"
        }
    ],
    "cpe": "cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*"
}

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-33245.json"