Open redirect in React Router - CVE-2026-53669
Published: July 22, 2026
Vulnerability identifier: #VU139181
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53669
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to redirect users to an external site.
The vulnerability exists due to open redirect in navigation mechanisms when processing attacker-supplied paths. A remote attacker can supply a crafted path to trigger an unexpected external navigation to redirect users to an external site.
Affected software
React Router
IBM SPSS Collaboration and Deployment Services
IBM SPSS Collaboration and Deployment Services
How to mitigate CVE-2026-53669
Install security update from vendor's website.
React Router - update to 7.18.0