Skip to main content
Mallory
Back to intelligence
open-source-dependency-vulnerabilityinternet-facing-service-vulnerabilitywidely-deployed-product-advisory

React Router Flaws Expose Servers to RCE, XSS, and DoS

Updated 2d agoFirst seen Jun 2, 20262 sources

Multiple vulnerabilities were disclosed in the widely used React Router npm package, including a reported remote code execution issue tracked as CVE-2026-42211 that researchers said could allow unauthenticated attackers to gain shell access when chained with an existing prototype pollution weakness. Additional flaws include CVE-2026-33245, a client-side cross-site scripting bug in redirect handling for applications using unstable React Server Components APIs, plus CVE-2026-34077 and CVE-2026-42342, two denial-of-service issues tied to serialization and manifest endpoint performance that can crash or degrade backend services.

The XSS issue affects React Router versions 7.7.0 through 7.13.1 when redirects originate from untrusted sources and use javascript: targets; applications not using the unstable RSC APIs or running in standard Declarative Mode are not impacted. Maintainers patched CVE-2026-33245 in React Router 7.13.2, while broader mitigation for the full set of reported issues requires upgrading to React Router 7.15.0 or Remix 2.17.5.

Share:
React Router Flaws Expose Servers to RCE, XSS, and DoS
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jun 4, 20262d ago

Maintainers issue broader React Router and Remix updates

Mitigations for the broader set of disclosed issues were made available by upgrading to React Router 7.15.0 or Remix 2.17.5. The update addressed the newly reported RCE, XSS, and DoS vulnerabilities.

React Router Vulnerabilities Patched in New Update

Researchers disclose multiple React Router vulnerabilities

Researchers reported multiple critical React Router vulnerabilities, including RCE flaw CVE-2026-42211, XSS flaw CVE-2026-33245, and DoS issues CVE-2026-34077 and CVE-2026-42342. The report said standard Declarative Mode was not affected.

React Router Vulnerabilities Patched in New Update
Jun 2, 20264d ago

React Router patches CVE-2026-33245 in version 7.13.2

React Router fixed CVE-2026-33245 in version 7.13.2. The vulnerability could be triggered through javascript: redirect targets from untrusted sources when applications used unstable RSC APIs.

CVE-2026-33245 - React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets

GitHub security advisory received for React Router XSS flaw

The advisory for CVE-2026-33245 was received by security-advisories@github.com. The flaw is a client-side XSS issue in React Router's unstable React Server Components redirect handling affecting versions 7.7.0 through 7.13.1.

CVE-2026-33245 - React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.