CVE-2026-53669
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in <Link> and useNavigate. This issue is a follow up to CVE-2025-68470 and has been fixed in version 7.18.0.
| CWE | CWE-601 |
| Vendor | remix-run |
| Product | react-router |
| Published | Jul 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for remix-run react-router
Be the first to know when new unknown vulnerabilities affecting remix-run react-router are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
remix-run / react-router
>= 6.0.0, < 7.18.0
References
github.com: https://github.com/remix-run/react-router/security/advisories/GHSA-wrjc-x8rr-h8h6 github.com: https://github.com/remix-run/react-router/pull/15176 github.com: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180 github.com: https://github.com/remix-run/react-router/releases/tag/[email protected] github.com: http://github.com/remix-run/react-router/pull/15176