React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if developers are creating redirect paths from untrusted content or via an open redirect. Note This does not impact applications that use Declarative Mode (<BrowserRouter>).
Stay updated with the latest patches and releases. Plan your sofware desisgn. Avoid common known vulnerabilities fixed by the open source community
Latest patch release: --
Latest minor release: 0.1.0
Latest major release: 1.23.2
Maintain your licence declarations and avoid unwanted licences to protect your IP the way you intended.
MIT - MIT License