React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if you are creating redirect paths from untrusted content or via an open redirect. There is no impact if Declarative Mode (<BrowserRouter>) is being used. This issue has been patched in @remix-run/router version 1.23.2 and react-router version 7.12.0.

Project Subscriptions

Vendors Products
Shopify Subscribe
React-router Subscribe
Remix-run\/react Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2w69-qvjg-hvjx React Router vulnerable to XSS via Open Redirects
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
https://access.redhat.com/errata/RHSA-2026:13542 cve-icon
https://access.redhat.com/errata/RHSA-2026:13548 cve-icon
https://access.redhat.com/errata/RHSA-2026:1517 cve-icon
https://access.redhat.com/errata/RHSA-2026:17468 cve-icon
https://access.redhat.com/errata/RHSA-2026:17469 cve-icon
https://access.redhat.com/errata/RHSA-2026:17474 cve-icon
https://access.redhat.com/errata/RHSA-2026:19712 cve-icon
https://access.redhat.com/errata/RHSA-2026:20041 cve-icon
https://access.redhat.com/errata/RHSA-2026:20042 cve-icon
https://access.redhat.com/errata/RHSA-2026:2147 cve-icon
https://access.redhat.com/errata/RHSA-2026:2148 cve-icon
https://access.redhat.com/errata/RHSA-2026:2149 cve-icon
https://access.redhat.com/errata/RHSA-2026:21658 cve-icon
https://access.redhat.com/errata/RHSA-2026:2350 cve-icon
https://access.redhat.com/errata/RHSA-2026:2456 cve-icon
https://access.redhat.com/errata/RHSA-2026:2568 cve-icon
https://access.redhat.com/errata/RHSA-2026:2572 cve-icon
https://access.redhat.com/errata/RHSA-2026:26413 cve-icon
https://access.redhat.com/errata/RHSA-2026:26420 cve-icon
https://access.redhat.com/errata/RHSA-2026:2694 cve-icon
https://access.redhat.com/errata/RHSA-2026:3087 cve-icon
https://access.redhat.com/errata/RHSA-2026:34100 cve-icon
https://access.redhat.com/errata/RHSA-2026:36651 cve-icon
https://access.redhat.com/errata/RHSA-2026:36882 cve-icon
https://access.redhat.com/errata/RHSA-2026:3782 cve-icon
https://access.redhat.com/errata/RHSA-2026:3958 cve-icon
https://access.redhat.com/errata/RHSA-2026:3959 cve-icon
https://access.redhat.com/errata/RHSA-2026:3960 cve-icon
https://access.redhat.com/errata/RHSA-2026:40118 cve-icon
https://access.redhat.com/errata/RHSA-2026:40945 cve-icon
https://access.redhat.com/errata/RHSA-2026:40984 cve-icon
https://access.redhat.com/errata/RHSA-2026:41064 cve-icon
https://access.redhat.com/errata/RHSA-2026:41928 cve-icon
https://access.redhat.com/errata/RHSA-2026:5633 cve-icon
https://access.redhat.com/errata/RHSA-2026:5636 cve-icon
https://access.redhat.com/errata/RHSA-2026:8218 cve-icon
https://access.redhat.com/errata/RHSA-2026:8229 cve-icon
https://access.redhat.com/errata/RHSA-2026:9848 cve-icon
https://access.redhat.com/security/cve/CVE-2026-22029 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2428412 cve-icon
https://github.com/remix-run/react-router/security/advisories/GHSA-2w69-qvjg-hvjx cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-22029 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22029.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-22029 cve-icon
History

Tue, 02 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description React Router is a router for React. In @remix-run/router version prior to 1.23.2. and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if you are creating redirect paths from untrusted content or via an open redirect. There is no impact if Declarative Mode (<BrowserRouter>) is being used. This issue has been patched in @remix-run/router version 1.23.2 and react-router version 7.12.0. React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if you are creating redirect paths from untrusted content or via an open redirect. There is no impact if Declarative Mode (<BrowserRouter>) is being used. This issue has been patched in @remix-run/router version 1.23.2 and react-router version 7.12.0.

Tue, 10 Feb 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Shopify
Shopify react-router
Shopify remix-run\/react
CPEs cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*
cpe:2.3:a:shopify:remix-run\/react:*:*:*:*:*:node.js:*:*
Vendors & Products Shopify
Shopify react-router
Shopify remix-run\/react

Tue, 13 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 12 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 10 Jan 2026 03:15:00 +0000

Type Values Removed Values Added
Description React Router is a router for React. In @remix-run/router version prior to 1.23.2. and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if you are creating redirect paths from untrusted content or via an open redirect. There is no impact if Declarative Mode (<BrowserRouter>) is being used. This issue has been patched in @remix-run/router version 1.23.2 and react-router version 7.12.0.
Title React Router vulnerable to XSS via Open Redirects
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-13T12:04:23.570Z

Reserved: 2026-01-05T22:30:38.718Z

Link: CVE-2026-22029

cve-icon Vulnrichment

Updated: 2026-08-13T12:04:23.570Z

cve-icon NVD

Status : Modified

Published: 2026-01-10T03:15:48.870

Modified: 2026-08-13T13:17:54.670

Link: CVE-2026-22029

cve-icon Redhat

Severity : Important

Publid Date: 2026-01-10T02:42:32Z

Links: CVE-2026-22029 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T19:15:16Z

Weaknesses