logo

Critical React Router Flaws Could Let Attackers Access or Modify Server Files

ID: fac247c0-3d93-5cce-8c14-5942815c637e

STIX ID: report--fac247c0-3d93-5cce-8c14-5942815c637e

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-01-12

Date Updated: 2026-04-22

Author: Divya

...
...

A critical vulnerability (CVSS 8.8) in createFileSessionStorage affecting @react-router/node (7.0.0–7.9.3), @remix-run/node (<=2.17.1) and @remix-run/deno (<=2.17.1) allows attackers to craft unsigned session cookies with directory traversal sequences to load or write files outside the session directory; attackers may expose sensitive data or overwrite files potentially enabling code execution. Users should upgrade to the patched versions and adopt signed cookies to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.