REDHAT-BUG-2428412: High severity npm/@remix-run/router vulnerability
React Router is a router for React. In @remix-run/router version prior to 1.23.2. and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if you are creating redirect paths from untrusted content or via an open redirect. There is no impact if Declarative Mode (<BrowserRouter>) is being used. This issue has been patched in @remix-run/router version 1.23.2 and react-router version 7.12.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@remix-run/routerto a version that resolves this vulnerability.Fixed in 1.23.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch react-router 7.0.0 through 7.11.0
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2428412?
The severity of REDHAT-BUG-2428412 is categorized as high with a score of 7.
How do I fix REDHAT-BUG-2428412?
To fix REDHAT-BUG-2428412, upgrade to @remix-run/router version 1.23.2 or higher and react-router version 7.11.1 or higher.
What vulnerabilities does REDHAT-BUG-2428412 address?
REHAT-BUG-2428412 addresses the issue of unsafe open navigation redirects in React Router and Remix.
Which versions of software are affected by REDHAT-BUG-2428412?
REDHAT-BUG-2428412 affects @remix-run/router versions prior to 1.23.2 and react-router versions 7.0.0 through 7.11.0.
What are the implications of not addressing REDHAT-BUG-2428412?
Not addressing REDHAT-BUG-2428412 could lead to potential exploitation through open navigation redirects, resulting in unsafe URLs.