top of page
perceptive_background_267k.jpg

React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exist…

Published:

9 januari 2026 om 23:00:00

Alert date:

10 januari 2026 om 13:10:58

Source:

nvd.nist.gov

Click to open the original link from this advisory

A Cross-Site Scripting (XSS) vulnerability exists in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json tags. The vulnerability affects @remix-run/react versions 1.15.0 through 2.17.0 and react-router versions 7.0.0 through 7.8.2. It allows arbitrary JavaScript execution during Server-Side Rendering (SSR) if untrusted content is used to generate the tag. The issue only impacts applications using Framework Mode, not Declarative Mode or Data Mode. Patches are available in @remix-run/react version 2.17.1 and react-router version 7.9.0.

Technical details

Mitigation steps:

Affected products:

React Router
@remix-run/react

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page