CVE-2025-59057: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in remix-run react-router
React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag. There is no impact if the application is being used in Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>). This issue has been patched in @remix-run/react version 2.17.1 and react-router version 7.9.0.
AI Analysis
Technical Summary
React Router versions 7.0.0 through 7.8.2 and @remix-run/react versions 1.15.0 through 2.17.0 contain a cross-site scripting vulnerability (CWE-79) in the meta() and <Meta> APIs when operating in Framework Mode. This vulnerability arises during server-side rendering when generating script:ld+json tags, which can lead to arbitrary JavaScript execution if untrusted input is used to generate these tags. The vulnerability does not affect applications running in Declarative Mode or Data Mode. The flaw has been addressed and patched in react-router version 7.9.0 and @remix-run/react version 2.17.1. The CVSS v3.1 base score is 7.6, indicating a high severity with network attack vector, low attack complexity, requiring privileges and user interaction, and impacting confidentiality and integrity with no availability impact. Vendor advisories from Red Hat confirm the vulnerability and patch availability.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the server-side rendered page when using the affected meta() or <Meta> APIs in Framework Mode with untrusted input. This can lead to confidentiality breaches and partial integrity loss of the rendered content. There is no impact if the application uses Declarative Mode or Data Mode. The vulnerability does not affect availability. No known exploits in the wild have been reported as of the publication date.
Mitigation Recommendations
An official fix is available. Users should upgrade to @remix-run/react version 2.17.1 or later and react-router version 7.9.0 or later to remediate this vulnerability. Applications not using Framework Mode for meta() or <Meta> APIs are not impacted. Review usage of these APIs with untrusted input and apply the patch accordingly. Refer to the Red Hat advisories for detailed update instructions. No additional mitigations are required if the application is not using the vulnerable APIs in Framework Mode.
CVE-2025-59057: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in remix-run react-router
Description
React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag. There is no impact if the application is being used in Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>). This issue has been patched in @remix-run/react version 2.17.1 and react-router version 7.9.0.
CVSS v3.1
Score 7.6high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
React Router versions 7.0.0 through 7.8.2 and @remix-run/react versions 1.15.0 through 2.17.0 contain a cross-site scripting vulnerability (CWE-79) in the meta() and <Meta> APIs when operating in Framework Mode. This vulnerability arises during server-side rendering when generating script:ld+json tags, which can lead to arbitrary JavaScript execution if untrusted input is used to generate these tags. The vulnerability does not affect applications running in Declarative Mode or Data Mode. The flaw has been addressed and patched in react-router version 7.9.0 and @remix-run/react version 2.17.1. The CVSS v3.1 base score is 7.6, indicating a high severity with network attack vector, low attack complexity, requiring privileges and user interaction, and impacting confidentiality and integrity with no availability impact. Vendor advisories from Red Hat confirm the vulnerability and patch availability.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the server-side rendered page when using the affected meta() or <Meta> APIs in Framework Mode with untrusted input. This can lead to confidentiality breaches and partial integrity loss of the rendered content. There is no impact if the application uses Declarative Mode or Data Mode. The vulnerability does not affect availability. No known exploits in the wild have been reported as of the publication date.
Mitigation Recommendations
An official fix is available. Users should upgrade to @remix-run/react version 2.17.1 or later and react-router version 7.9.0 or later to remediate this vulnerability. Applications not using Framework Mode for meta() or <Meta> APIs are not impacted. Review usage of these APIs with untrusted input and apply the patch accordingly. Refer to the Red Hat advisories for detailed update instructions. No additional mitigations are required if the application is not using the vulnerable APIs in Framework Mode.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2025-09-08T16:19:26.173Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2025-59057","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:3958","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:3960","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:3782","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19712","vendor":"Red Hat"}]
Threat ID: 6961c40f19784dcf52ace861
Added to database: 01/10/2026, 03:14:23 UTC
Last enriched: 07/15/2026, 08:20:39 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 237
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.