๐Ÿ›ก๏ธ CVE-2025-61686
๐Ÿ”ด CVSS 9.5 โ€” Critical โœ… No Known Exploit CWE-22 NVD
9.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/node (or @remix-run/node/@remix-run/deno in Remix v2) with an unsigned cookie, it is possible for an attacker to cause the session to try to read/write from a location outside the specified session file directory. The success of the attack would depend on the permissions of the web server process to access those files. Read files cannot be returned directly to the attacker. Session file reads would only succeed if the file matched the expected session file format. If the file matched the session file format, the data would be populated into the server side session but not directly returned to the attacker unless the application logic returned specific session information. This issue has been patched in @react-router/node version 7.9.4, @remix-run/deno version 2.17.2, and @remix-run/node version 2.17.2.

Details

Severity CRITICAL
CVSS Score 9.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CWE CWE-22
Public Exploit โœ… No
Source NVD
Published 2026-01-08
Updated 2026-06-02
Modified 2026-02-03
Fix URL N/A

Affected Packages

Software From version Fixed in
@react-router/node โ€” โ€”
@remix-run/deno โ€” โ€”
@remix-run/node โ€” โ€”
react-router\/node 7.0.0 7.9.4
remix-run\/deno โ€” 2.17.2
remix-run\/node โ€” 2.17.2

Patch Gap Protection

Running software with known vulnerabilities?

BotEraser can help reduce exposure by blocking IPs associated with exploit activity โ€” even before a patch is available.

Start Free โ†’

No credit card required  ยท  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.