The disclosure of critical vulnerabilities in React Router has caused alarm in the web development community and cybersecurity teams . The security flaws allow, under certain circumstances, unauthorized access or even modification of files on the server through directory traversal attacks.

The core vulnerability, CVE-2025-61686, has received a CVSS v3 score of 9.8, making it an immediate priority for remediation.
React Router: Which packages are affected?
The problem is not limited to a single library, but concerns multiple packages in the React Router and Remix ecosystems, which are widely used in modern server-side rendering and full-stack JavaScript applications.
See also: Exploiting VMware zero-day vulnerabilities
Specifically, they are affected by:
- @react-router/node from version 7.0.0 to 7.9.3
- @remix-run/deno up to version 2.17.1
- @remix-run/node up to version 2.17.1
The widespread use of these packages means that a large number of applications may be exposed, especially in production environments.

The CVE-2025-61686 vulnerability in simple terms
CVE-2025-61686 is a vulnerability in the createFileSessionStorage() when used in conjunction with unsigned cookies. Attackers can manipulate session cookies to force the application to read or write files outside the specified session directory.
Simply put, the system trusts data it shouldn't, paving the way for malicious manipulation of file paths.
The actual extent of the damage depends on the permissions of the web server process and the overall file system.
See also: Critical vulnerability in jsPDF allows arbitrary file reading on Node.js installations
Why is the problem considered so serious?
Directory traversal attacks have long been one of the most dangerous types of vulnerabilities, as they can lead to cascading effects. Combined with other weaknesses, such a gap can be a springboard for further exploitation, data theft, or even remote code execution.

Fixes and safe releases
The React Router and Remix development teams have already released updates that address the issue. Developers are urged to upgrade to the following versions immediately:
- @react-router/node: 7.9.4 or later
- @remix-run/deno: 2.17.2 or later
- @remix-run/node: 2.17.2 or later
The new versions implement stricter path validation and sanitization in the session storage mechanism.
See also: Coolify: 11 critical security vulnerabilities allow complete server compromise
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What organizations should do immediately
According to a related update on GitHub, organizations using the affected versions should take immediate action. In addition to upgrading, it is recommended to:
- Check file permissions and restrict system access
- Inspection of session storage implementations for use of unsigned cookies
- Monitoring suspicious or unusual session cookie patterns
- Apply additional file system restrictions , where possible
The incident serves as a reminder that even mature and widely used frameworks can hide critical vulnerabilities, making regular updating and security auditing an integral part of modern software development.
