npm package report

Is @react-router/node safe?

1 known vulnerability, worst severity CRITICAL.

cvss
9.1

how bad it is if exploited, out of 10

epss
17.6%

chance of exploitation in the next 30 days

xyz score
5.3

CyberXYZ composite, out of 10

fig. 01 — GHSA-9583-h5hc-x8cw, the advisory selected below

// advisories

GHSA-9583-h5hc-x8cw

CRITICALCVE-2025-61686

If applications use createFileSessionStorage() from @react-router/node (or @remix-run/node/@remix-run/deno in Remix v2) with an [unsigned cookie](https://reactrouter.com/explanation/sessions-and-cookies#signing-cookies), it is possible for an attacker to cause the session to try to read/write from a location outside the specified session file directory. The success of the attack would depend on th

Affected
>= 7.0.0, <= 7.9.3
Fixed in
7.9.4
Weakness
CWE-22
Published
2026-01-08
Source
github

GHSANVDMITREreferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 03:26 UTC. The most recent advisory here was published 2026-01-08. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is @react-router/node safe? npm package security report | CyberXYZ