Skip to content

chore(deps): update dependency react-router@>=7.0.0 <7.18.0 to v7.18.2 [security] - #511

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-react-router-7-0-0-7-18-0-vulnerability
Open

chore(deps): update dependency react-router@>=7.0.0 <7.18.0 to v7.18.2 [security]#511
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-react-router-7-0-0-7-18-0-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
react-router@>=7.0.0 <7.18.0 (source) [7.18.17.18.2](https://renovatebot.com/diffs/npm/react-router@>=7.0.0 <7.18.0/7.18.1/7.18.2) age confidence

React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration

CVE-2026-53666 / GHSA-337j-9hxr-rhxg

More information

Details

If application code allows attacker supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for attacker to trigger unexpected constructor execution on the client which would trigger outbound network traffic. This is only possible with very specific (and unlikely) application layer code.

[!NOTE]
This does not impact your application if you are using Declarative Mode. This only impacts Framework Mode and Data Mode applications doing manual SSR/hydration

Severity

  • CVSS Score: 6.1 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


React Router: Open redirect via backslash in and useNavigate (CVE-2025-68470 bypass)

CVE-2026-53669 / GHSA-wrjc-x8rr-h8h6

More information

Details

This is a follow up to CVE-2025-68470. React Router was alerted to certain scenarios in which the fix there was incomplete so there still existed some scenarios where attacker supplied paths passed to navigation mechanisms could result in unexpected external navigations.

Severity

  • CVSS Score: 5.1 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response

GHSA-qwww-vcr4-c8h2

More information

Details

This is a follow up to CVE-2026-22030 to address related CSRF flows in unstable RSC code paths.

[!NOTE]
This only affects your application if you are using the unstable RSC APIs

Severity

  • CVSS Score: 7.1 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

remix-run/react-router (react-router@>=7.0.0 <7.18.0)

v7.18.2: v7.18.2

Compare Source

See the changelog for release notes: https://github.com/remix-run/react-router/blob/v7/CHANGELOG.md#v7182


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@cla-assistant

cla-assistant Bot commented Jul 29, 2026

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@github-actions

github-actions Bot commented Jul 29, 2026

Copy link
Copy Markdown

🚀 Preview Environment Ready!

32 deployed applications (click to expand)
Name Status URL
tanstack-start-basic-example ✅ Active https://testuser-70413-tanstack-start-basic-example-zephy-8b174d5... ↗
rspress-v2 ✅ Active https://testuser-70432-rspress-v2-zephyr-packages-zephyrc-c674c0b... ↗
sample-webpack-application ✅ Active https://testuser-70424-sample-webpack-application-zephyr--ef187c2... ↗
mf-react-rsbuild-provider ✅ Active https://testuser-70428-mf-react-rsbuild-provider-zephyr-p-2469a55... ↗
rsbuild-sample-app ✅ Active https://testuser-70427-rsbuild-sample-app-zephyr-packages-5aba9fd... ↗
lynx ✅ Active https://testuser-70420-lynx-zephyr-packages-zephyrcloudio-e945a48... ↗
hono-app ✅ Active https://testuser-70408-hono-app-zephyr-packages-zephyrclo-3b8df9c... ↗
sample-rspack-application ✅ Active https://testuser-70426-sample-rspack-application-zephyr-p-e7454ba... ↗
elysia-app ✅ Active https://testuser-70407-elysia-app-zephyr-packages-zephyrc-040f48b... ↗
rspack-mf-remote ✅ Active https://testuser-70419-rspack-mf-remote-zephyr-packages-z-522b9a1... ↗
vite-remote ✅ Active https://testuser-70411-vite-remote-zephyr-packages-zephyr-7d85ec2... ↗
team-green ✅ Active https://testuser-70422-team-green-zephyr-packages-zephyrc-d337aae... ↗
mf-react-rsbuild ✅ Active https://testuser-70430-mf-react-rsbuild-zephyr-packages-z-b758a0f... ↗
rspress-v2-ssg ✅ Active https://testuser-70433-rspress-v2-ssg-zephyr-packages-zep-e212336... ↗
modern-js ✅ Active https://testuser-70431-modern-js-zephyr-packages-zephyrcl-ee3e484... ↗
zephyr-cli-test ✅ Active https://testuser-70429-zephyr-cli-test-zephyr-packages-ze-8e2ff56... ↗
vite-host ✅ Active https://testuser-70409-vite-host-zephyr-packages-zephyrcl-e505074... ↗
rollup-sample-lib ✅ Active https://testuser-70406-rollup-sample-lib-zephyr-packages--64a3df3... ↗
vite-react-ts ✅ Active https://testuser-70410-vite-react-ts-zephyr-packages-zeph-d2ab615... ↗
rolldown-react ✅ Active https://testuser-70404-rolldown-react-zephyr-packages-zep-2ddf56d... ↗
vite-rspack ✅ Active https://testuser-70415-vite-rspack-zephyr-packages-zephyr-9b962a8... ↗
team-red ✅ Active https://testuser-70423-team-red-zephyr-packages-zephyrclo-c5f0d6d... ↗
vite-webpack ✅ Active https://testuser-70421-vite-webpack-zephyr-packages-zephy-c343625... ↗
rspress-v1 ✅ Active https://testuser-70434-rspress-v1-zephyr-packages-zephyrc-013d5ba... ↗
nuxt ✅ Active https://testuser-70435-nuxt-zephyr-packages-zephyrcloudio-5b88311... ↗
rspack-nx-mf-host ✅ Active https://testuser-70425-rspack-nx-mf-host-zephyr-packages--797fe0a... ↗
rspack-mf-host ✅ Active https://testuser-70418-rspack-mf-host-zephyr-packages-zep-8454841... ↗
team-blue ✅ Active https://testuser-70417-team-blue-zephyr-packages-zephyrcl-b374778... ↗
rspack-nx-mf-remote ✅ Active https://testuser-70416-rspack-nx-mf-remote-zephyr-package-34ca224... ↗
vinext-hackernews ✅ Active https://testuser-70414-vinext-hackernews-zephyr-packages--de50f27... ↗
parcel-react ✅ Active https://testuser-70405-parcel-react-zephyr-packages-zephy-0373e49... ↗
astro-blog ✅ Active https://testuser-70412-astro-blog-zephyr-packages-zephyrc-d6eafb9... ↗

Details:

  • Latest Commit: f1cde43
  • Updated at: 8/3/2026, 8:22:12 PM

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 60a13695e5

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread pnpm-lock.yaml Outdated
'@swc/helpers': 0.5.23
lru-cache: 10.4.3
react-router: 7.18.1(react-dom@19.2.8(react@19.2.8))(react@19.2.8)
react-router: 8.3.0(react-dom@19.2.8(react@19.2.8))(react@19.2.8)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep Modern.js on one router major

For Modern.js workspaces that install @modern-js/runtime with @modern-js/plugin-ssg (the repo's examples/modern-js does), this lockfile entry makes @modern-js/runtime-utils resolve react-router@8.3.0 while the same lockfile still gives @modern-js/plugin-ssg its optional react-router-dom@7.18.1, whose own dependency is react-router@7.18.1. That creates two React Router copies/majors in one app; providers and hooks/components from different router copies do not share React Router context, so SSG/runtime routing can fail after install. Please upgrade the Modern.js/SSG stack to a router-v8-compatible version or keep this override on a compatible v7 fix.

Useful? React with 👍 / 👎.

@renovate
renovate Bot force-pushed the renovate/npm-react-router-7-0-0-7-18-0-vulnerability branch from 60a1369 to 400cdb6 Compare July 30, 2026 18:48

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 400cdb6c95

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread pnpm-workspace.yaml Outdated
js-yaml@>=4.0.0 <4.3.0: 4.3.0
postcss: 8.5.23
react-router@>=7.0.0 <7.18.0: 7.18.1
react-router@>=7.0.0 <7.18.0: 8.3.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Update all affected router copies

For the GHSA-qwww-vcr4-c8h2 affected range (react-router >=7.12.0 <8.3.0), this override only catches packages that request <7.18.0. The lockfile still keeps the catalog react-router-dom@7.18.1 consumers in examples/rollup-sample-lib and examples/rspack-nx-mf, and those snapshots pull react-router@7.18.1, so this security update leaves vulnerable v7 copies installed while the advisory remains ignored in auditConfig. Please either update/remove the remaining v7 DOM consumers or stop suppressing the advisory for the copies that cannot be upgraded yet.

Useful? React with 👍 / 👎.

@renovate
renovate Bot force-pushed the renovate/npm-react-router-7-0-0-7-18-0-vulnerability branch 9 times, most recently from 07a2b47 to 54fb46d Compare August 5, 2026 15:39
@renovate
renovate Bot force-pushed the renovate/npm-react-router-7-0-0-7-18-0-vulnerability branch from 54fb46d to 4107f10 Compare August 7, 2026 15:50
@renovate renovate Bot changed the title chore(deps): update dependency react-router@>=7.0.0 <7.18.0 to v8 [security] chore(deps): update dependency react-router@>=7.0.0 <7.18.0 to v8 [security] - autoclosed Aug 7, 2026
@renovate renovate Bot closed this Aug 7, 2026
@renovate
renovate Bot deleted the renovate/npm-react-router-7-0-0-7-18-0-vulnerability branch August 7, 2026 18:48
@renovate renovate Bot changed the title chore(deps): update dependency react-router@>=7.0.0 <7.18.0 to v8 [security] - autoclosed chore(deps): update dependency react-router@>=7.0.0 <7.18.0 to v7.18.2 [security] Aug 9, 2026
@renovate renovate Bot reopened this Aug 9, 2026
@renovate
renovate Bot force-pushed the renovate/npm-react-router-7-0-0-7-18-0-vulnerability branch 3 times, most recently from 1e17080 to ecbeda9 Compare August 11, 2026 18:55

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ecbeda9687

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread pnpm-lock.yaml
'@swc/helpers': 0.5.23
lru-cache: 10.4.3
react-router: 7.18.1(react-dom@19.2.8(react@19.2.8))(react@19.2.8)
react-router: 7.18.2(react-dom@19.2.8(react@19.2.8))(react@19.2.8)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep Modern.js on one router copy

Fresh evidence in the current lockfile is that this changed resolution puts @modern-js/runtime-utils on react-router 7.18.2 while examples/modern-js installs both @modern-js/plugin-ssg and @modern-js/runtime (examples/modern-js/package.json:15-16), and the SSG side still resolves react-router-dom 7.18.1 (pnpm-lock.yaml:19817) whose dependency remains react-router 7.18.1 (pnpm-lock.yaml:31877). That leaves the Modern SSG/runtime app with two React Router module instances, so providers/hooks from the SSG DOM copy and runtime copy will not share router context; please align react-router-dom to the same fixed router version or keep the runtime override on the shared version.

Useful? React with 👍 / 👎.

@renovate
renovate Bot force-pushed the renovate/npm-react-router-7-0-0-7-18-0-vulnerability branch from ecbeda9 to 0c5ae18 Compare August 11, 2026 19:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants