Description
If applications use createFileSessionStorage() from @react-router/node (or @remix-run/node/@remix-run/deno in Remix v2) with an unsigned cookie, it is possible for an attacker to cause the session to try to read/write from a location outside the specified session file directory.
Recommendation
Update the @remix-run/deno package to the latest compatible version. Followings are version details:
- Affected version(s): <= 2.17.1
- Patched version(s): 2.17.2
References
Could your website be exposed too?
SmartScanner can check your website for React Router has Path Traversal in File Session Storage and gives you actionable findings to investigate.
Start a free scanRelated Issues
- jsPDF has Local File Inclusion/Path Traversal vulnerability - CVE-2025-68428
- SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory - CVE-2026-34522
- Rollup 4 has Arbitrary File Write via Path Traversal - CVE-2026-27606
- React Router has XSS Vulnerability - CVE-2025-59057


