react-router是Remix开源的一个 React 的声明式路由。 react-router存在路径遍历漏洞,该漏洞源于使用未签名cookie时,会话可能尝试从指定会话文件目录之外的位置读取或写入。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| remix-run | react-router | @react-router/node >= 7.0.0, < 7.9.4 |
affected |
@remix-run/deno < 2.17.2 |
affected | ||
@remix-run/node < 2.17.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| remix-run | react-router | @react-router/node >= 7.0.0, < 7.9.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2025-61686复现的dockerfile与poc | https://github.com/FlowerWitch/CVE-2025-61686_docker | POC Details |
| 2 | None | https://github.com/Kai-One001/React-Router-CVE-2025-61686- | POC Details |
| 3 | React Router's createFileSessionStorage() in certain versions allows unsigned cookies to be manipulated, enabling file system access outside the session directory. | https://github.com/boroeurnprach/CVE-2025-61686-PoC | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-21884 | 8.2 HIGH | React Router SSR XSS in ScrollRestoration |
| CVE-2026-22029 | 8.0 HIGH | React Router vulnerable to XSS via Open Redirects |
| CVE-2025-59057 | 7.6 HIGH | React Router has XSS Vulnerability |
| CVE-2026-22030 | 6.5 MEDIUM | React Router has CSRF issue in Action/Server Action Request Processing |
| CVE-2025-68470 | 6.5 MEDIUM | React Router has unexpected external redirect via untrusted paths |
No comments yet