CVE-2026-33245 - React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets
CVE ID :CVE-2026-33245 Published : June 2, 2026, 8:16 p.m. | 57 minutes ago Description :React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS)...