React Router SSR XSS in ScrollRestoration
GHSA-8v8x-cx79-35w7 · CVE-2026-21884
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
A XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/storageKey props during Server-Side Rendering which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the keys.
[!NOTE]
This does not impact applications if developers have disabled server-side rendering in Framework Mode, or if they are using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>).
References
- WEB https://github.com/remix-run/react-router/security/advisories/GHSA-8v8x-cx79-35w7
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-21884
- WEB https://github.com/remix-run/react-router/pull/14705
- WEB https://github.com/remix-run/react-router/commit/c89c32c562a7723c45ee71dab1c892acaf7a608d
- WEB https://access.redhat.com/errata/RHSA-2026:19712
- WEB https://access.redhat.com/errata/RHSA-2026:3782
- WEB https://access.redhat.com/errata/RHSA-2026:3958
- WEB https://access.redhat.com/errata/RHSA-2026:3960
- WEB https://access.redhat.com/security/cve/CVE-2026-21884
- WEB https://bugzilla.redhat.com/show_bug.cgi?id=2428421
- PACKAGE https://github.com/remix-run/react-router
- WEB https://github.com/remix-run/react-router/blob/react-router%407.12.0/CHANGELOG.md#v7120
- WEB https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21884.json
Ready to move
Start Securing
Free, no credit card | First findings in minutes