Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8v8x-cx79-35w7 | React Router SSR XSS in ScrollRestoration |
Sat, 28 Feb 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Fri, 30 Jan 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shopify
Shopify react-router Shopify remix-run\/react |
|
| CPEs | cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:* cpe:2.3:a:shopify:remix-run\/react:*:*:*:*:*:node.js:*:* |
|
| Vendors & Products |
Shopify
Shopify react-router Shopify remix-run\/react |
Tue, 13 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 12 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 10 Jan 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/storageKey props during Server-Side Rendering which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the keys. There is no impact if server-side rendering in Framework Mode is disabled, or if Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>) is being used. This issue has been patched in @remix-run/react version 2.17.3 and react-router version 7.12.0. | |
| Title | React Router SSR XSS in ScrollRestoration | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-26T15:04:51.084Z
Reserved: 2026-01-05T17:24:36.928Z
Link: CVE-2026-21884
Updated: 2026-01-12T18:11:06.386Z
Status : Analyzed
Published: 2026-01-10T03:15:48.673
Modified: 2026-01-30T18:19:22.727
Link: CVE-2026-21884
OpenCVE Enrichment
Updated: 2026-04-18T07:15:25Z
Github GHSA