Declarative routing for React
96%
Total Score
100
100
100
75
100
One of 19 workflows uses pull_request_target, which warrants review because that trigger can be sensitive, but there are no detected untrusted checkouts or script injections.
Seven workflows lack top-level permission declarations and two declare write access, leaving some workflow privilege boundaries less explicit than ideal.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-55685 react-router is vulnerable to Uncontrolled Resource Consumption in versions 7.0.0 - 7.18.0. | 7.0.0 - 7.18.0 | High |
CVE-2026-53669 react-router is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 6.0.0 - 7.18.0. | 6.0.0 - 7.18.0 | Medium |
CVE-2026-53668 react-router is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 7.9.6 - 7.12.0. | 7.9.6 - 7.12.0 | Medium |
CVE-2026-53667 react-router is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 7.11.0 - 7.18.0. | 7.11.0 - 7.18.0 | Medium |
CVE-2026-53666 react-router is vulnerable to Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') in versions 6.4.0 - 7.18.0. | 6.4.0 - 7.18.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
cookie-es Version ^3.1.1 | — | — |
@remix-run/route-pattern Version ^0.22.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.