Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-qwww-vcr4-c8h2
  • npm/react-router
React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response 24 Jul
  • Fix available
  • Severity - 7.1 (High)
GHSA-chx6-hx7r-mcp5
  • npm/react-router
React Router: Unauthenticated Denial of Service via Inefficient Route Matching 24 Jul
  • Fix available
  • Severity - 8.7 (High)
GHSA-wrjc-x8rr-h8h6
  • npm/react-router
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass) 23 Jul
  • Fix available
  • Severity - 5.1 (Medium)
GHSA-jjmj-jmhj-qwj2
  • npm/react-router
  • npm/react-router-dom
React Router: Open redirect leading to XSS 23 Jul
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-h8fp-f39c-q6mh
  • npm/react-router
React Router: RSCErrorHandler Missing Protocol Validation (XSS) 23 Jul
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-337j-9hxr-rhxg
  • npm/react-router
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration 23 Jul
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-84g9-w2xq-vcv6
  • npm/@remix-run/server-runtime
  • npm/react-router
React Router: Potential CSRF via PUT/PATCH/DELETE document requests 15 Jun
  • Fix available
  • Severity - 3.1 (Low)
GHSA-rxv8-25v2-qmq8
  • npm/react-router
  • npm/turbo-stream
React Router vulnerable to Denial of Service via reflected user input in single-fetch 04 Jun
  • Fix available
  • Severity - 7.5 (High)
GHSA-8x6r-g9mw-2r78
  • npm/@remix-run/server-runtime
  • npm/react-router
React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint 03 Jun
  • Fix available
  • Severity - 7.5 (High)
GHSA-49rj-9fvp-4h2h
  • npm/react-router
React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE 03 Jun
  • Fix available
  • Severity - 8.1 (High)
GHSA-2j2x-hqr9-3h42
  • npm/@remix-run/router
  • npm/react-router
React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation 03 Jun
  • Fix available
  • Severity - 6.6 (Medium)
GHSA-8646-j5j9-6r62
  • npm/react-router
React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets 03 Jun
  • Fix available
  • Severity - 8.0 (High)
GHSA-f22v-gfqf-p8f3
  • npm/react-router
React Router has stored XSS via unescaped Location header in prerendered redirect HTML 03 Jun
  • Fix available
  • Severity - 5.4 (Medium)
MAL-2026-1838
  • npm/react-router-on-navigation
Malicious code in react-router-on-navigation (npm) 18 Mar
  • No fix available
GHSA-h5cw-625j-3rxh
  • npm/@remix-run/server-runtime
  • npm/react-router
React Router has CSRF issue in Action/Server Action Request Processing 08 Jan
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-2w69-qvjg-hvjx
  • npm/@remix-run/router
  • npm/react-router
React Router vulnerable to XSS via Open Redirects 08 Jan
  • Fix available
  • Severity - 8.0 (High)