OsVault/npm/react-router
npm

react-router

22 known vulnerabilities · 0 critical · 0 high

GHSA-49rj-9fvp-4h2h

React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE

Published Jun 3, 2026
GHSA-8646-j5j9-6r62

React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets

Published Jun 3, 2026
GHSA-8x6r-g9mw-2r78

React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint

Published Jun 3, 2026
GHSA-f22v-gfqf-p8f3

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

Published Jun 3, 2026
CVE-2025-59057

React Router has XSS Vulnerability

Published Jan 8, 2026
CVE-2025-68470

React Router has unexpected external redirect via untrusted paths

Published Jan 8, 2026
CVE-2025-43865

React Router allows pre-render data spoofing on React-Router framework mode

Published Apr 24, 2025
CVE-2026-22029

React Router vulnerable to XSS via Open Redirects

Published Jan 8, 2026
CVE-2026-22030

React Router has CSRF issue in Action/Server Action Request Processing

Published Jan 8, 2026
CVE-2026-21884

React Router SSR XSS in ScrollRestoration

Published Jan 8, 2026
GHSA-rxv8-25v2-qmq8

React Router vulnerable to Denial of Service via reflected user input in single-fetch

Published Jun 4, 2026
GHSA-2j2x-hqr9-3h42

React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation

Published Jun 3, 2026
GHSA-84g9-w2xq-vcv6

React Router: Potential CSRF via PUT/PATCH/DELETE document requests

Published Jun 15, 2026
MAL-2026-2978

Malicious code in @oec-settlement/react-router (npm)

Published Apr 22, 2026
MAL-2026-1838

Malicious code in react-router-on-navigation (npm)

Published Mar 18, 2026
MAL-2026-3465

Malicious code in @tanstack/react-router (npm)

Published May 11, 2026
MAL-2026-3467

Malicious code in @tanstack/react-router-ssr-query (npm)

Published May 11, 2026
MAL-2023-733

Malicious code in react-router-packages (npm)

Published Jun 13, 2023
MAL-2025-192977

Malicious code in shopify-app-react-router (npm)

Published Dec 30, 2025
MAL-2024-9004

Malicious code in meraki-react-router (npm)

Published Sep 27, 2024
MAL-2026-3466

Malicious code in @tanstack/react-router-devtools (npm)

Published May 11, 2026
MAL-2025-191137

Malicious code in okta-react-router-6 (npm)

Published Nov 24, 2025
Check your entire dependency tree at onceRun dependency scan →