Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

remix-run — Vulnerabilities & Security Advisories 21

Browse all 21 CVE security advisories affecting remix-run. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Remix-run is a web framework for building modern, server-rendered web applications with a focus on performance and developer experience. Historically, it has been associated with vulnerabilities like cross-site scripting (XSS) due to improper input handling and server-side request forgery (SSRF) from inadequate URL validation. While no major security incidents have been widely documented, the 9 CVEs on record highlight recurring issues in template rendering and route handling. The framework's emphasis on server-first architecture reduces certain client-side risks but requires careful implementation to prevent common web vulnerabilities like XSS and SSRF.

Found 21 results / 21 Clear Filters
Top products by remix-run: react-router
CVE ID Title CVSS Severity Published
CVE-2026-53669 React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass) — react-router CWE-601 5.1 Medium 2026-07-27
CVE-2026-55685 React Router: Unauthenticated Denial of Service via Inefficient Route Matching — react-router CWE-400 8.7 High 2026-07-27
CVE-2026-53668 React Router: Open redirect can lead to XSS — react-router CWE-601 6.9 Medium 2026-07-27
CVE-2026-53667 React Router: Cross-site Scripting is Possible due to Missing RSCErrorHandler Protocol Validation (Incomplete fix for CVE-2026-53667) — react-router CWE-79 6.9 Medium 2026-07-27
CVE-2026-53666 React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration — react-router CWE-470 6.1 Medium 2026-07-27
CVE-2026-53663 React Router: `handleDocumentRequest` CSRF check covers `POST` only; PUT/PATCH/DELETE bypass — react-router CWE-352 3.1 Low 2026-06-22
CVE-2026-42342 React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint — react-router CWE-400 7.5 High 2026-06-02
CVE-2026-42211 React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE — react-router CWE-502 8.1 High 2026-06-02
CVE-2026-40181 React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation — react-router CWE-601 6.6 Medium 2026-06-02
CVE-2026-34077 React Router vulnerable to Denial of Service via reflected user input in single-fetch — react-router CWE-770 7.5 High 2026-06-02
CVE-2026-33245 React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets — react-router CWE-79 8.0 High 2026-06-02
CVE-2026-33244 React Router has stored XSS via unescaped Location header in prerendered redirect HTML — react-router CWE-79 5.4 Medium 2026-06-02
CVE-2026-22030 React Router has CSRF issue in Action/Server Action Request Processing — react-router CWE-346 6.5 Medium 2026-01-10
CVE-2026-22029 React Router vulnerable to XSS via Open Redirects — react-router CWE-79 8.0 High 2026-01-10
CVE-2026-21884 React Router SSR XSS in ScrollRestoration — react-router CWE-79 8.2 High 2026-01-10
CVE-2025-61686 React Router has Path Traversal in File Session Storage — react-router CWE-22 9.1 Critical 2026-01-10
CVE-2025-59057 React Router has XSS Vulnerability — react-router CWE-79 7.6 High 2026-01-10
CVE-2025-68470 React Router has unexpected external redirect via untrusted paths — react-router CWE-601 6.5 Medium 2026-01-10
CVE-2025-43865 React Router allows pre-render data spoofing on React-Router framework mode — react-router CWE-345 8.2 High 2025-04-25
CVE-2025-43864 React Router allows a DoS via cache poisoning by forcing SPA mode — react-router CWE-755 7.5 High 2025-04-25
CVE-2025-31137 Remix and React Router allow URL manipulation via Host / X-Forwarded-Host headers — react-router CWE-444 5.3 - 2025-04-01

This page lists every published CVE security advisory associated with remix-run. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.