Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f22v-gfqf-p8f3

Опубликовано: 03 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

When using React Router v7 Framework Mode with Pre-rendering enabled, an improper neutralization of the HTTP Location header value can permit Cross-Site Scripting (XSS) in statically generated HTML files if the redirect location comes from an untrusted source.

[!NOTE] This does not impact your React Router application if you are using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>).

Пакеты

Наименование

react-router

npm
Затронутые версииВерсия исправления

>= 7.5.1, < 7.13.2

7.13.2

EPSS

Процентиль: 4%
0.00144
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
redhat
2 месяца назад

React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header value can permit Cross-Site Scripting (XSS) in the statically generated HTML files if the redirect location comes from an untrusted source. This does not impact applications using Declarative Mode (`<BrowserRouter>`) or Data Mode (`createBrowserRouter/<RouterProvider>`). This is patched in version 7.13.2.

CVSS3: 5.4
nvd
2 месяца назад

React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header value can permit Cross-Site Scripting (XSS) in the statically generated HTML files if the redirect location comes from an untrusted source. This does not impact applications using Declarative Mode (`<BrowserRouter>`) or Data Mode (`createBrowserRouter/<RouterProvider>`). This is patched in version 7.13.2.

EPSS

Процентиль: 4%
0.00144
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79