CVE-2026-34077
remix-run react-router, turbo-stream, turbo stream 취약점
React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2.
- 대응 우선순위
- 점검
- CVSS
- 7.5
- EPSS
- 0.29% 백분위 21.6% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.06.03