CVE-2026-21884

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
10/01/2026
Last modified:
30/01/2026

Description

React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's API in Framework Mode when using the getKey/storageKey props during Server-Side Rendering which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the keys. There is no impact if server-side rendering in Framework Mode is disabled, or if Declarative Mode () or Data Mode (createBrowserRouter/) is being used. This issue has been patched in @remix-run/react version 2.17.3 and react-router version 7.12.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:* 7.0.0 (including) 7.11.0 (including)
cpe:2.3:a:shopify:remix-run\/react:*:*:*:*:*:node.js:*:* 2.17.3 (excluding)