Skip to content
Critical React Router Vulnerabilities Allow Server File Access

Critical React Router Vulnerabilities Allow Server File Access

First seen 12 Jan 2026, 12:58 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Security researchers have identified critical vulnerabilities in React Router that enable attackers to access or modify server files through directory traversal. These flaws impact multiple packages within the React Router ecosystem and have a CVSS v3 score of 9.8, indicating critical severity.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (3)

Following this threat?

Track CVE-2025-61686 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed