Skip to content

Update dependency react-router-dom to v6.30.5 [SECURITY] - #4331

Merged
olemartinorg merged 1 commit into
mainfrom
renovate/npm-react-router-dom-vulnerability
Sep 3, 2026
Merged

Update dependency react-router-dom to v6.30.5 [SECURITY]#4331
olemartinorg merged 1 commit into
mainfrom
renovate/npm-react-router-dom-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
react-router-dom (source) 6.30.36.30.5 age confidence

React Router: Open redirect leading to XSS

CVE-2026-53668 / GHSA-jjmj-jmhj-qwj2

More information

Details

Applications with open redirects could permit attacker crafted links to result in redirects to unexpected external location or XSS vectors.

Severity

  • CVSS Score: 6.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

remix-run/react-router (react-router-dom)

v6.30.4

Compare Source


Configuration

📅 Schedule: (in timezone Europe/Oslo)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added backport-ignore This PR is a new feature and should not be cherry-picked onto release branches kind/dependencies Pull requests that update a dependency file labels Aug 18, 2026
@renovate renovate Bot changed the title Update dependency react-router-dom to v6.30.5 [SECURITY] Update dependency react-router-dom to v6.30.5 [SECURITY] - autoclosed Aug 19, 2026
@renovate renovate Bot closed this Aug 19, 2026
@renovate
renovate Bot deleted the renovate/npm-react-router-dom-vulnerability branch August 19, 2026 00:08
@renovate renovate Bot changed the title Update dependency react-router-dom to v6.30.5 [SECURITY] - autoclosed Update dependency react-router-dom to v6.30.5 [SECURITY] Aug 21, 2026
@renovate renovate Bot reopened this Aug 21, 2026
@renovate
renovate Bot force-pushed the renovate/npm-react-router-dom-vulnerability branch 2 times, most recently from dcd684a to edea662 Compare August 21, 2026 21:14
@olemartinorg
olemartinorg merged commit 41fd731 into main Sep 3, 2026
48 of 53 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport-ignore This PR is a new feature and should not be cherry-picked onto release branches kind/dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant