Security researchers have identified critical vulnerabilities in React Router that allow attackers to access or modify server files via directory traversal.
The flaws affect multiple packages within the React Router ecosystem and carry a CVSS v3 score of 9.8, classifying them as critical severity.