REDHAT-BUG-2428426: XSS
React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag. There is no impact if the application is being used in Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>). This issue has been patched in @remix-run/react version 2.17.1 and react-router version 7.9.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@remix-run/reactto a version that resolves this vulnerability.Fixed in 2.17.1 - Upgrade
Upgrade
react-routerto a version that resolves this vulnerability.Fixed in 7.9.0
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2428426?
The severity of REDHAT-BUG-2428426 is high with a rating of 7.
How do I fix REDHAT-BUG-2428426?
To fix REDHAT-BUG-2428426, you should upgrade @remix-run/react to versions above 2.17.0 and react-router to versions above 7.8.2.
What vulnerability type is REDHAT-BUG-2428426?
REDHAT-BUG-2428426 is categorized as an XSS vulnerability.
Which software is affected by REDHAT-BUG-2428426?
The affected software includes npm/@remix-run/react versions 1.15.0 through 2.17.0 and npm/react-router versions 7.0.0 through 7.8.2.
When was REDHAT-BUG-2428426 published?
REDHAT-BUG-2428426 was published on January 10, 2026.