HomeSecurityReact Router: Critical vulnerability allows directory traversal attacks

React Router: Critical vulnerability allows directory traversal attacks

The disclosure of critical vulnerabilities in React Router has caused alarm in the web development community and cybersecurity teams . The security flaws allow, under certain circumstances, unauthorized access or even modification of files on the server through directory traversal attacks.

React Router

The core vulnerability, CVE-2025-61686, has received a CVSS v3 score of 9.8, making it an immediate priority for remediation.

React Router: Which packages are affected?

The problem is not limited to a single library, but concerns multiple packages in the React Router and Remix ecosystems, which are widely used in modern server-side rendering and full-stack JavaScript applications.

See also: Exploiting VMware zero-day vulnerabilities

Specifically, they are affected by:

  • @react-router/node from version 7.0.0 to 7.9.3
  • @remix-run/deno up to version 2.17.1
  • @remix-run/node up to version 2.17.1

The widespread use of these packages means that a large number of applications may be exposed, especially in production environments.

React Router: Critical vulnerability allows directory traversal attacks

The CVE-2025-61686 vulnerability in simple terms

CVE-2025-61686 is a vulnerability in the createFileSessionStorage() when used in conjunction with unsigned cookies. Attackers can manipulate session cookies to force the application to read or write files outside the specified session directory.

Simply put, the system trusts data it shouldn't, paving the way for malicious manipulation of file paths.

The actual extent of the damage depends on the permissions of the web server process and the overall file system.

See also: Critical vulnerability in jsPDF allows arbitrary file reading on Node.js installations

Why is the problem considered so serious?

Directory traversal attacks have long been one of the most dangerous types of vulnerabilities, as they can lead to cascading effects. Combined with other weaknesses, such a gap can be a springboard for further exploitation, data theft, or even remote code execution.

React Router: Critical vulnerability allows directory traversal attacks

Fixes and safe releases

The React Router and Remix development teams have already released updates that address the issue. Developers are urged to upgrade to the following versions immediately:

  • @react-router/node: 7.9.4 or later
  • @remix-run/deno: 2.17.2 or later
  • @remix-run/node: 2.17.2 or later

The new versions implement stricter path validation and sanitization in the session storage mechanism.

See also: Coolify: 11 critical security vulnerabilities allow complete server compromise

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

What organizations should do immediately

According to a related update on GitHub, organizations using the affected versions should take immediate action. In addition to upgrading, it is recommended to:

  • Check file permissions and restrict system access
  • Inspection of session storage implementations for use of unsigned cookies
  • Monitoring suspicious or unusual session cookie patterns
  • Apply additional file system restrictions , where possible

The incident serves as a reminder that even mature and widely used frameworks can hide critical vulnerabilities, making regular updating and security auditing an integral part of modern software development.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS