Declarative routing for React
97%
Total Score
100
97
91
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-55685 react-router is vulnerable to Uncontrolled Resource Consumption in versions 7.0.0 - 7.18.0. | 7.0.0 - 7.18.0 | High |
CVE-2026-53669 react-router is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 6.0.0 - 7.18.0. | 6.0.0 - 7.18.0 | Medium |
CVE-2026-53667 react-router is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 7.11.0 - 7.18.0. | 7.11.0 - 7.18.0 | Medium |
CVE-2026-53666 react-router is vulnerable to Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') in versions 6.4.0 - 7.18.0. | 6.4.0 - 7.18.0 | Medium |
AIKIDO-2026-740941 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. react-router is vulnerable to Deserialization of Untrusted Data in versions 7.0.0 - 7.17.0. | 7.0.0 - 7.17.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
cookie-es Version ^3.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant