


Perceptive Security
SOC/SIEM Consultancy

React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exist…
Published:
9 januari 2026 om 23:00:00
Alert date:
10 januari 2026 om 13:10:58
Source:
nvd.nist.gov
A Cross-Site Scripting (XSS) vulnerability exists in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json tags. The vulnerability affects @remix-run/react versions 1.15.0 through 2.17.0 and react-router versions 7.0.0 through 7.8.2. It allows arbitrary JavaScript execution during Server-Side Rendering (SSR) if untrusted content is used to generate the tag. The issue only impacts applications using Framework Mode, not Declarative Mode or Data Mode. Patches are available in @remix-run/react version 2.17.1 and react-router version 7.9.0.
Technical details
Mitigation steps:
Affected products:
React Router
@remix-run/react
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-59057
https://github.com/remix-run/react-router/security/advisories/GHSA-3cgp-3xvw-98x8
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
