GHSA-8v8x-cx79-35w7HighCVSS 8.2
React Router SSR XSS in ScrollRestoration
🔗 CVE IDs covered (1)
📋 Description
A XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/storageKey props during Server-Side Rendering which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the keys.
[!NOTE] This does not impact applications if developers have disabled server-side rendering in Framework Mode, or if they are using Declarative Mode (
<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>).
🎯 Affected products2
- npm/react-router:>= 7.0.0, < 7.12.0
- npm/@remix-run/react:< 2.17.3
🔗 References (13)
- https://github.com/remix-run/react-router/security/advisories/GHSA-8v8x-cx79-35w7
- https://nvd.nist.gov/vuln/detail/CVE-2026-21884
- https://github.com/remix-run/react-router/pull/14705
- https://github.com/remix-run/react-router/commit/c89c32c562a7723c45ee71dab1c892acaf7a608d
- https://access.redhat.com/errata/RHSA-2026:19712
- https://access.redhat.com/errata/RHSA-2026:3782
- https://access.redhat.com/errata/RHSA-2026:3958
- https://access.redhat.com/errata/RHSA-2026:3960
- https://access.redhat.com/security/cve/CVE-2026-21884
- https://bugzilla.redhat.com/show_bug.cgi?id=2428421
- https://github.com/remix-run/react-router/blob/react-router%407.12.0/CHANGELOG.md#v7120
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21884.json
- https://github.com/advisories/GHSA-8v8x-cx79-35w7