CVE-2025-61686
remix-run react-router, Cryostat 4, Gatekeeper 3 취약점
- 대응 우선순위
- 우선
- CVSS
- 9.1
- EPSS
- 16.1% 백분위 96.5% · 2026.06.27 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.01.10
FIRST EPSS 기준 악용 가능성이 높은 취약점
React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/node (or @remix-run/node/@remix-run/deno in Remix v2) with an unsigned cookie, it is possible for an attacker to cause the session to try to read/write from a location outside the specified session file directory. The success of the attack would depend on the permissions of the web server process to access those files. Read files cannot be returned directly...
공급사 remix-run
제품 react-router, Cryostat 4, Gatekeeper 3
영향 버전 @react-router/node >= 7.0.0, < 7.9.4, @remix-run/deno < 2.17.2, @remix-run/node < 2.17.2, >= 7.0.0 < 7.9.4, < 2.17.2
수정 버전 7.9.4, 2.17.2
CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CWE CWE-22
EPSS 데이터 기준일 2026.06.27