CVE-2026-33245
Aliases:GHSA-8646-j5j9-6r62CGA-39hg-hx29-h2gpCGA-48x7-r354-8mwqCGA-928x-6mwj-9w8pCGA-q9c9-7qhg-23h2
Advisory lineage Upstream: 0 Downstream: 1
Downstream
Analyzed
Published: 02 Jun 2026, 17:14
Last modified:03 Jun 2026, 19:09
Vulnerability Summary
Overall Risk (default)
medium
32/100 CVSS Score
8 HIGH
v3.1 (cve.org)
EPSS Score
0.19% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
02 Jun 2026, 17:14
Published
Vulnerability first disclosed
03 Jun 2026, 19:09
Last Modified
Vulnerability information updated
Description
React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2.
CVSS Metrics
- v3.1•HIGH•Score: 8CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
- v3.1•MEDIUM•Score: 4.7CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Trends
Current EPSS score: 0.19%• Percentile: 9%
Techniques & Countermeasures
- CWE-79•Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Affected Systems
- chainguard•airflow-2
all
- chainguard•airflow-core-2
all
- Npm•react-router
≥ 7.7.0, < 7.13.2
- remix-run•react-router
≥ 7.7.0, < 7.13.2
- shopify•react-router
≥ 7.7.0, < 7.13.2