React Router Open Redirect Vulnerability in Redirect Function

Vulnerability

A moderate open redirect vulnerability has been identified in React Router versions 7.0.0 prior to 7.14.1 and 6.7.0 prior to 6.30.4. The issue arises when certain URLs passed to the redirect function are interpreted as protocol-relative URLs, allowing redirection to external domains. The impact of this vulnerability depends on the application's validation of URLs before processing the redirect. Notably, this issue does not affect applications using Declarative Mode with <BrowserRouter>.

Impact

Exploitation of this vulnerability allows for open redirect, where users can be redirected to an external domain, potentially leading to phishing or other malicious activities.

Remediation

Users can upgrade to React Router versions 7.14.1 or 6.30.4 to address this vulnerability.

Added: Jun 2, 2026, 8:32 PM
Updated: Jun 2, 2026, 8:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.2
exploitability
7.4
remediation
0.0
relevance
9.8
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.