React Router has XSS Vulnerability
High severity
GitHub Reviewed
Published
Jan 8, 2026
in
remix-run/react-router
•
Updated Jan 11, 2026
Description
Published to the GitHub Advisory Database
Jan 8, 2026
Reviewed
Jan 8, 2026
Published by the National Vulnerability Database
Jan 10, 2026
Last updated
Jan 11, 2026
A XSS vulnerability exists in in React Router's
meta()/<Meta>APIs in Framework Mode when generatingscript:ld+jsontags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag.Note
This does not impact applications using Declarative Mode (
<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>).References