๐Ÿ” CVE Alert

CVE-2026-53669

UNKNOWN 0.0

React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in <Link> and useNavigate. This issue is a follow up to CVE-2025-68470 and has been fixed in version 7.18.0.

CWE CWE-601
Vendor remix-run
Product react-router
Published Jul 27, 2026
Stay Ahead of the Next One

Get instant alerts for remix-run react-router

Be the first to know when new unknown vulnerabilities affecting remix-run react-router are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

remix-run / react-router
>= 6.0.0, < 7.18.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/remix-run/react-router/security/advisories/GHSA-wrjc-x8rr-h8h6 github.com: https://github.com/remix-run/react-router/pull/15176 github.com: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180 github.com: https://github.com/remix-run/react-router/releases/tag/[email protected] github.com: http://github.com/remix-run/react-router/pull/15176