Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f22v-gfqf-p8f3 | React Router has stored XSS via unescaped Location header in prerendered redirect HTML |
Fri, 19 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 03 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shopify
Shopify react-router |
|
| CPEs | cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Shopify
Shopify react-router |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Remix-run
Remix-run react-router |
|
| Vendors & Products |
Remix-run
Remix-run react-router |
Tue, 02 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header value can permit Cross-Site Scripting (XSS) in the statically generated HTML files if the redirect location comes from an untrusted source. This does not impact applications using Declarative Mode (`<BrowserRouter>`) or Data Mode (`createBrowserRouter/<RouterProvider>`). This is patched in version 7.13.2. | |
| Title | React Router has stored XSS via unescaped Location header in prerendered redirect HTML | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-02T17:28:13.207Z
Reserved: 2026-03-18T02:42:27.509Z
Link: CVE-2026-33244
Updated: 2026-06-02T17:28:09.695Z
Status : Analyzed
Published: 2026-06-02T17:16:28.030
Modified: 2026-06-03T16:54:00.463
Link: CVE-2026-33244
OpenCVE Enrichment
Updated: 2026-06-02T20:50:50Z
Github GHSA