GHSA-9583-h5hc-x8cw
CRITICALCVE-2025-61686If applications use createFileSessionStorage() from @react-router/node (or @remix-run/node/@remix-run/deno in Remix v2) with an [unsigned cookie](https://reactrouter.com/explanation/sessions-and-cookies#signing-cookies), it is possible for an attacker to cause the session to try to read/write from a location outside the specified session file directory. The success of the attack would depend on th
- Affected
- <= 2.17.1
- Fixed in
- 2.17.2
- Weakness
- CWE-22
- Published
- 2026-01-08
- Source
- github