React Router
- >= 7.0.0, < 7.14.1
- >= 6.7.0, < 6.30.4
A moderate open redirect vulnerability has been identified in React Router versions 7.0.0 prior to 7.14.1 and 6.7.0 prior to 6.30.4. The issue arises when certain URLs passed to the redirect function are interpreted as protocol-relative URLs, allowing redirection to external domains. The impact of this vulnerability depends on the application's validation of URLs before processing the redirect. Notably, this issue does not affect applications using Declarative Mode with <BrowserRouter>.
Exploitation of this vulnerability allows for open redirect, where users can be redirected to an external domain, potentially leading to phishing or other malicious activities.
Users can upgrade to React Router versions 7.14.1 or 6.30.4 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.