AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-55685 was published on 2026-07-27T22:17:40.860Z. This vulnerability affects React Router versions 7.0.0 through 7.17.0, allowing unauthenticated targeted requests to access the manifest endpoint, potentially causing denial-of-service attacks. The issue does not impact applications using Declarative Mode or Data [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T22:17:31.377Z and has not been modified since then. The React Router library, used for client-side routing in React applications, contains a vulnerability that allows for Open Redirect attacks. This issue arises from the improper handling of backslashes in the <Link> component and useNavigate hoo [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T22:17:30.937Z and has not been modified since then. CVE-2026-53666 affects React Router, a router for React, in versions 6.4.0 through 7.17.0. Under specific conditions in Framework Mode and Data Mode with manual SSR/hydration, an attacker could trigger unexpected client-side constructor executio [truncated]
CVE-2025-61686 is a critical vulnerability in React Router, a popular router for React applications. The vulnerability affects versions 7.0.0 through 7.9.3 of @react-router/node, and prior versions of @remix-run/deno and @remix-run/node. An attacker can exploit this vulnerability to cause the session to try to read/write from a location outside the specified session file directory, potentially leading to [truncated]
CVE-2025-59057 is a high-severity XSS vulnerability affecting React Router's meta()/<Meta> APIs in Framework Mode. The issue exists in @remix-run/react versions 1.15.0 through 2.17.0 and react-router versions 7.0.0 through 7.8.2. An attacker could exploit this vulnerability to execute arbitrary JavaScript during Server-Side Rendering (SSR) if untrusted content is used to generate script:ld+json tags. The [truncated]