MEDIUM 6.9
GHSA-jjmj-jmhj-qwj2
React Router: Open redirect leading to XSS
Quick fix
GHSA-jjmj-jmhj-qwj2 — react-router: upgrade to the fixed version with the command below.
npm install react-router@7.13.0 Details
Applications with open redirects could permit attacker crafted links to result in redirects to unexpected external location or XSS vectors.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm / react-router-dom
Introduced in:
6.30.2 No fixed version published yet for react-router-dom (npm). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/remix-run/react-router/security/advisories/GHSA-jjmj-jmhj-qwj2 [WEB]
- https://github.com/remix-run/react-router/pull/14718 [WEB]
- https://github.com/remix-run/react-router/commit/3a5b5ad0e5cf9918c646509563f5c41a89226ff3 [WEB]
- https://github.com/remix-run/react-router [PACKAGE]
- https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180 [WEB]
- https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0 [WEB]