← Vulnerability feed

Vulnerability record · CVE-2026-40181 · published 2 June 2026

CVE-2026-40181: Shopify react-router open redirect vulnerability

Shopify · React Router

React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigger an open redirect to an external domain due to path values starting with // being reinterpreted as protocol-relative URLs. The level of impact depends on the validation done by the application prior to returning the redirect. This does not impact applications using Declarative Mode (<BrowserRouter>). This is patched in versions 7.14.1 and 6.30.4.

6.6 CVSS 4.0 Medium EPSS 0.26% · top 84.0% CWE-601 · Open redirect
6.6CVSS 4.0 base score
0.26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
4 Aug 2026Last modified by NVD

Description

React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigger an open redirect to an external domain due to path values starting with // being reinterpreted as protocol-relative URLs. The level of impact depends on the validation done by the application prior to returning the redirect. This does not impact applications using Declarative Mode (<BrowserRouter>). This is patched in versions 7.14.1 and 6.30.4.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-40181 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2026-55685Shopify react-router uncontrolled resource consumption vulnerabilityReact Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests t…EPSS 0.71%8.2CVE-2026-21884Shopify react-router cross-site scripting vulnerabilityReact Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in…EPSS 0.54%8.1CVE-2026-42211Shopify react-router deserialization of untrusted data vulnerabilityReact Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unaut…EPSS 0.62%7.6CVE-2025-59057Shopify react-router cross-site scripting vulnerabilityReact Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerab…EPSS 0.51%7.5CVE-2026-42342Shopify react-router uncontrolled resource consumption vulnerabilityReact Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime,…EPSS 0.46%7.5CVE-2026-34077Shopify react-router allocation without limits vulnerabilityReact Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is…EPSS 0.45%6.9CVE-2026-53668Shopify react-router cross-site scripting vulnerabilityReact Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable…EPSS 0.34%6.5CVE-2026-22030Shopify react-router origin validation error vulnerabilityReact Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Rem…EPSS 0.19%

Source: NIST National Vulnerability Database (record CVE-2026-40181), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.