npm package report

Is @remix-run/deno safe?

1 known vulnerability, worst severity CRITICAL.

cvss
9.1

how bad it is if exploited, out of 10

epss
17.6%

chance of exploitation in the next 30 days

xyz score
5.2

CyberXYZ composite, out of 10

fig. 01 — GHSA-9583-h5hc-x8cw, the advisory selected below

// advisories

GHSA-9583-h5hc-x8cw

CRITICALCVE-2025-61686

If applications use createFileSessionStorage() from @react-router/node (or @remix-run/node/@remix-run/deno in Remix v2) with an [unsigned cookie](https://reactrouter.com/explanation/sessions-and-cookies#signing-cookies), it is possible for an attacker to cause the session to try to read/write from a location outside the specified session file directory. The success of the attack would depend on th

Affected
<= 2.17.1
Fixed in
2.17.2
Weakness
CWE-22
Published
2026-01-08
Source
github

GHSANVDMITREreferencereferencereferencereference


// dependencies

2 direct, 1 carrying known advisories, worst HIGH

Sign in for dependency paths and remediation

// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 02:45 UTC. The most recent advisory here was published 2026-01-08. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is @remix-run/deno safe? npm package security report | CyberXYZ