Critical React Router Flaws Could Let Attackers Access or Modify Server Files
ID: fac247c0-3d93-5cce-8c14-5942815c637e
STIX ID: report--fac247c0-3d93-5cce-8c14-5942815c637e
Feed Name: GBHackers
Threat Score
A critical vulnerability (CVSS 8.8) in createFileSessionStorage affecting @react-router/node (7.0.0–7.9.3), @remix-run/node (<=2.17.1) and @remix-run/deno (<=2.17.1) allows attackers to craft unsigned session cookies with directory traversal sequences to load or write files outside the session directory; attackers may expose sensitive data or overwrite files potentially enabling code execution. Users should upgrade to the patched versions and adopt signed cookies to mitigate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
