Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33244

Опубликовано: 02 июн. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP Location header value can permit Cross-Site Scripting (XSS) in the statically generated HTML files if the redirect location comes from an untrusted source. This does not impact applications using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>). This is patched in version 7.13.2.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*
Версия от 7.5.1 (включая) до 7.13.2 (исключая)

EPSS

Процентиль: 4%
0.00144
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
redhat
2 месяца назад

React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header value can permit Cross-Site Scripting (XSS) in the statically generated HTML files if the redirect location comes from an untrusted source. This does not impact applications using Declarative Mode (`<BrowserRouter>`) or Data Mode (`createBrowserRouter/<RouterProvider>`). This is patched in version 7.13.2.

CVSS3: 5.4
github
2 месяца назад

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

EPSS

Процентиль: 4%
0.00144
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79