React Router
- >= 7.5.1, < 7.13.2
A Cross-Site Scripting (XSS) vulnerability has been identified in React Router versions 7.5.1 prior to 7.13.2. This issue arises when Framework Mode is used with pre-rendering enabled, allowing improper handling of the HTTP Location header. If the redirect location is sourced from an untrusted entity, it can lead to XSS in the statically generated HTML files. This vulnerability does not affect applications using Declarative Mode or Data Mode.
Exploitation of this vulnerability allows for Cross-Site Scripting (XSS) attacks, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Users can upgrade to React Router version 7.13.2 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.