← Vulnerability feed

Vulnerability record · CVE-2026-22029 · published 10 January 2026

CVE-2026-22029: Shopify remix-run\/react cross-site scripting vulnerability

Shopify · Remix Run\/React

React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if you are creating redirect paths from untrusted content or via an open redirect. There is no impact if Declarative Mode (<BrowserRouter>) is being used. This issue has been patched in @remix-run/router version 1.23.2 and react-router version 7.12.0.

6.1 CVSS 3.1 Medium EPSS 0.88% · top 42.5% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
0.88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
42References
10 Sep 2026Last modified by NVD

Description

React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if you are creating redirect paths from untrusted content or via an open redirect. There is no impact if Declarative Mode (<BrowserRouter>) is being used. This issue has been patched in @remix-run/router version 1.23.2 and react-router version 7.12.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/remix-run/react-router/security/advisories/GHSA-2w69-qvjg-hvjx Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:13542
https://access.redhat.com/errata/RHSA-2026:13548
https://access.redhat.com/errata/RHSA-2026:1517
https://access.redhat.com/errata/RHSA-2026:17468
https://access.redhat.com/errata/RHSA-2026:17469
https://access.redhat.com/errata/RHSA-2026:17474
https://access.redhat.com/errata/RHSA-2026:19712
https://access.redhat.com/errata/RHSA-2026:20041
https://access.redhat.com/errata/RHSA-2026:20042
https://access.redhat.com/errata/RHSA-2026:2147
https://access.redhat.com/errata/RHSA-2026:2148
https://access.redhat.com/errata/RHSA-2026:2149
https://access.redhat.com/errata/RHSA-2026:21658
https://access.redhat.com/errata/RHSA-2026:2350
https://access.redhat.com/errata/RHSA-2026:2456
https://access.redhat.com/errata/RHSA-2026:2568
https://access.redhat.com/errata/RHSA-2026:2572
https://access.redhat.com/errata/RHSA-2026:26413
https://access.redhat.com/errata/RHSA-2026:26420
https://access.redhat.com/errata/RHSA-2026:2694
https://access.redhat.com/errata/RHSA-2026:3087
https://access.redhat.com/errata/RHSA-2026:34100
https://access.redhat.com/errata/RHSA-2026:36651
https://access.redhat.com/errata/RHSA-2026:36882
https://access.redhat.com/errata/RHSA-2026:3782
https://access.redhat.com/errata/RHSA-2026:3958
https://access.redhat.com/errata/RHSA-2026:3959
https://access.redhat.com/errata/RHSA-2026:3960
https://access.redhat.com/errata/RHSA-2026:40118
https://access.redhat.com/errata/RHSA-2026:40945
https://access.redhat.com/errata/RHSA-2026:40984
https://access.redhat.com/errata/RHSA-2026:41064
https://access.redhat.com/errata/RHSA-2026:41928
https://access.redhat.com/errata/RHSA-2026:5633
https://access.redhat.com/errata/RHSA-2026:5636
https://access.redhat.com/errata/RHSA-2026:8218
https://access.redhat.com/errata/RHSA-2026:8229
https://access.redhat.com/errata/RHSA-2026:9848
https://access.redhat.com/security/cve/CVE-2026-22029

Track CVE-2026-22029 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2026-55685Shopify react-router uncontrolled resource consumption vulnerabilityReact Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests t…EPSS 0.71%8.2CVE-2026-21884Shopify react-router cross-site scripting vulnerabilityReact Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in…EPSS 0.54%8.1CVE-2026-42211Shopify react-router deserialization of untrusted data vulnerabilityReact Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unaut…EPSS 0.62%7.6CVE-2025-59057Shopify react-router cross-site scripting vulnerabilityReact Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerab…EPSS 0.51%7.5CVE-2026-42342Shopify react-router uncontrolled resource consumption vulnerabilityReact Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime,…EPSS 0.46%7.5CVE-2026-34077Shopify react-router allocation without limits vulnerabilityReact Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is…EPSS 0.45%6.9CVE-2026-53668Shopify react-router cross-site scripting vulnerabilityReact Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable…EPSS 0.34%6.6CVE-2026-40181Shopify react-router open redirect vulnerabilityReact Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigg…EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2026-22029), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.