GHSA-3cgp-3xvw-98x8HighCVSS 7.6
React Router has XSS Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag.
[!NOTE] This does not impact applications using Declarative Mode (
<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>).
🎯 Affected products2
- npm/react-router:>= 7.0.0, <= 7.8.2
- npm/@remix-run/react:>= 1.15.0, <= 2.17.0
🔗 References (14)
- https://github.com/remix-run/react-router/security/advisories/GHSA-3cgp-3xvw-98x8
- https://nvd.nist.gov/vuln/detail/CVE-2025-59057
- https://github.com/remix-run/react-router/pull/14316
- https://github.com/remix-run/react-router/commit/0e774855797fcb3c7538c269158f4541beb55a1b
- https://access.redhat.com/errata/RHSA-2026:19712
- https://access.redhat.com/errata/RHSA-2026:3782
- https://access.redhat.com/errata/RHSA-2026:3958
- https://access.redhat.com/errata/RHSA-2026:3960
- https://access.redhat.com/security/cve/CVE-2025-59057
- https://bugzilla.redhat.com/show_bug.cgi?id=2428426
- https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v790
- https://github.com/remix-run/react-router/releases/tag/[email protected]
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59057.json
- https://github.com/advisories/GHSA-3cgp-3xvw-98x8