react-router
npm6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting react-routerpage 1 of 1
- CVE-2025-43864HIGHCVSS 7.5EG 7.5✓ Fixed in 7.5.22025-04-25
React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an application to switch to SPA mode by adding a header to the request. If the application uses SSR and is forced to switch t…
- CVE-2025-43865HIGHCVSS 8.2EG 8.2✓ Fixed in 7.5.22025-04-25
React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values �…
- CVE-2025-59057HIGHCVSS 7.6EG 7.6✓ Fixed in 7.9.02026-01-10
React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating scr…
- CVE-2026-21884HIGHCVSS 8.2EG 8.2✓ Fixed in 7.12.02026-01-10
React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/storage…
- CVE-2026-22029HIGHCVSS 8.0EG 8.0✓ Fixed in 7.12.02026-01-10
React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Dat…
- CVE-2026-22030MEDIUMCVSS 6.5EG 6.5✓ Fixed in 7.12.02026-01-10
React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using ser…
Check whether react-router is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for react-router CVEs against the assets you own.
Start Free Scan →