How to use this reference
The maintainer lists 1.3.4 as fixed. Editorial lesson: distinguish identifier unpredictability, integrity of client-returned state, storage selection and authorization for each storage operation. A securely generated identifier does not prove that a later input was generated by the server. Keep session storage isolated from unrelated application state, validate the accepted identifier contract and require integrity protection appropriate to the session design. These are defensive principles, not a verified description of the patch implementation.
Before reading
- Server-side session stores and cookie integrity concepts
- Key-value namespaces and operation-specific authorization concepts
Context and limits
- The optional KV adapter and unsigned-cookie configuration are both required. The advisory does not establish exposure in every React Router application, platform-wide access or cross-customer access.
- No production incident, reward, finder, verified patch implementation or 1.3.4 release date is established by the reviewed advisory. It lists no known CVE. The publishing account is not treated as an author or finder.
- The linked filesystem-session advisory concerns a separate storage implementation; its mechanics and impact are not imported into this record.
Sources and provenance
- Vercel React Router KV session-storage advisory GHSA-7wjf-49rm-77gx Vercel · reviewed 2026-10-04
Record reviewed 2026-10-04. Snapshot 53796974ace8. Open the complete JSON contract.