Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8646-j5j9-6r62 | React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets |
Tue, 23 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 04 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shopify
Shopify react-router |
|
| CPEs | cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Shopify
Shopify react-router |
Wed, 03 Jun 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Remix-run
Remix-run react-router |
|
| Vendors & Products |
Remix-run
Remix-run react-router |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2. | |
| Title | React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-03T19:09:34.483Z
Reserved: 2026-03-18T02:42:27.509Z
Link: CVE-2026-33245
Updated: 2026-06-03T19:09:14.803Z
Status : Analyzed
Published: 2026-06-02T20:16:34.367
Modified: 2026-06-04T18:43:39.807
Link: CVE-2026-33245
OpenCVE Enrichment
Updated: 2026-06-03T10:55:30Z
Github GHSA