logo

Critical React Router Flaws: CVE-2025-61686 Exposes Server Files

ID: 4b9ee578-4985-524b-b144-f6a8df1f06d6

STIX ID: report--4b9ee578-4985-524b-b144-f6a8df1f06d6

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-12

Date Updated: 2026-04-23

Author: Ddos

...
...

This report details multiple security vulnerabilities in react-router and @remix-run packages—most notably CVE-2025-61686 (CVSS 9.1) in createFileSessionStorage that can allow session-based reads/writes outside the intended directory, several high-severity XSS issues (including Meta Component XSS, ScrollRestoration XSS, and an SPA open-redirect XSS), and additional CSRF and external redirect logic flaws; maintainers have released patches and users should verify and update affected versions immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.