GHSA-8v8x-cx79-35w7
Dashboard / Vulnerabilities / GHSA-8v8x-cx79-35w7
Summary: React Router SSR XSS in ScrollRestoration
Details: A XSS vulnerability exists in in React Router's `<ScrollRestoration>` API in [Framework Mode](https://reactrouter.com/start/modes#framework) when using the `getKey`/`storageKey` props during Server-Side Rendering which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the keys. > [!NOTE] > This does not impact applications if developers have [disabled server-side rendering](https://reactrouter.com/how-to/spa) in Framework Mode, or if they are using [Declarative Mode](https://reactrouter.com/start/modes#declarative) (`<BrowserRouter>`) or [Data Mode](https://reactrouter.com/start/modes#data) (`createBrowserRouter`/`<RouterProvider>`).
References: https://github.com/remix-run/react-router/security/advisories/GHSA-8v8x-cx79-35w7, https://nvd.nist.gov/vuln/detail/CVE-2026-21884, https://github.com/remix-run/react-router/pull/14705, https://github.com/remix-run/react-router/commit/c89c32c562a7723c45ee71dab1c892acaf7a608d, https://access.redhat.com/errata/RHSA-2026:19712, https://access.redhat.com/errata/RHSA-2026:3782, https://access.redhat.com/errata/RHSA-2026:3958, https://access.redhat.com/errata/RHSA-2026:3960, https://access.redhat.com/security/cve/CVE-2026-21884, https://bugzilla.redhat.com/show_bug.cgi?id=2428421, https://github.com/remix-run/react-router, https://github.com/remix-run/react-router/blob/react-router%407.12.0/CHANGELOG.md#v7120, https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21884.json
Affected packages
Package
Name: react-router
Purl: pkg:npm/react-router
Affected ranges
Type: SEMVER
Events:
