


Perceptive Security
SOC/SIEM Consultancy

React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unauthorized rem…
Published:
1 juni 2026 om 22:00:00
Alert date:
2 juni 2026 om 21:03:34
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
React Router versions 7.0.0 through 7.14.1 contain a vulnerability in Framework Mode that allows unauthorized remote code execution through external requests. The attack requires an existing prototype pollution vulnerability in the application code and uses a 2-step attack process. Applications using Declarative Mode or Data Mode are not affected. The vulnerability is patched in version 7.14.2.
Technical details
Mitigation steps:
Affected products:
React Router
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42211
https://github.com/remix-run/react-router/security/advisories/GHSA-49rj-9fvp-4h2h
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
