Описание
React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/ APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag. There is no impact if the application is being used in Declarative Mode () or Data Mode (createBrowserRouter/). This issue has been patched in @remix-run/react version 2.17.1 and react-router version 7.9.0.
The cross site scripting flaw has been discovered in the npm react-router package. A XSS vulnerability exists in in React Router's meta()/ APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Build of Kueue | kueue/kueue-must-gather-rhel9 | Not affected | ||
| Red Hat Build of Kueue | kueue/kueue-operator-bundle | Not affected | ||
| Red Hat Build of Kueue | kueue/kueue-rhel9 | Not affected | ||
| Red Hat Build of Kueue | kueue/kueue-rhel9-operator | Not affected | ||
| Red Hat Enterprise Linux 10 | ipa | Not affected | ||
| Red Hat Enterprise Linux 9 | ipa | Not affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-gen-ai-rhel9 | Affected | ||
| Red Hat Ansible Automation Platform 2.6 for RHEL 9 | automation-platform-ui | Fixed | RHSA-2026:3958 | 06.03.2026 |
| Red Hat Ansible Automation Platform 2.6 | ansible-automation-platform-26/gateway-rhel9 | Fixed | RHSA-2026:3960 | 06.03.2026 |
| Red Hat OpenShift AI 2.25 | rhoai/odh-dashboard-rhel9 | Fixed | RHSA-2026:3782 | 04.03.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.6 High
CVSS3
Связанные уязвимости
React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag. There is no impact if the application is being used in Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>). This issue has been patched in @remix-run/react version 2.17.1 and react-router version 7.9.0.
Уязвимость пакетов npm React Router и Remix, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольный JavaScript-код
EPSS
7.6 High
CVSS3