Security: remix-run/react-router
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
RSC Mode CSRF Bypass Allows Action Execution Before 400 ResponseGHSA-qwww-vcr4-c8h2 published
Jul 22, 2026 by brophdawg11Moderate -
Open redirect leading to XSSGHSA-jjmj-jmhj-qwj2 published
Jul 22, 2026 by brophdawg11Moderate -
Unauthenticated Denial of Service in React Router __manifest endpointGHSA-chx6-hx7r-mcp5 published
Jul 22, 2026 by brophdawg11High -
RSCErrorHandler Missing Protocol Validation (XSS)GHSA-h8fp-f39c-q6mh published
Jul 22, 2026 by brophdawg11Moderate -
Arbitrary client-side constructor injection via React Router SSR HydrationGHSA-337j-9hxr-rhxg published
Jul 22, 2026 by brophdawg11Moderate -
Unexpected external redirect via untrusted paths (CVE-2025-68470 bypass)GHSA-wrjc-x8rr-h8h6 published
Jul 22, 2026 by brophdawg11Moderate -
Potential CSRF via PUT/PATCH/DELETE document requestsGHSA-84g9-w2xq-vcv6 published
Jun 2, 2026 by brophdawg11Low -
Potential RCE via 2-step attack chained onto existing prototype pollution vulnerabilityGHSA-49rj-9fvp-4h2h published
Jun 2, 2026 by brophdawg11High -
Same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretationGHSA-2j2x-hqr9-3h42 published
Jun 2, 2026 by brophdawg11Moderate -
DoS via unbounded path expansion in __manifest endpointGHSA-8x6r-g9mw-2r78 published
Jun 2, 2026 by brophdawg11High