Description
react-router-dom is pinned at 6.30.6 and has two remaining moderate-severity advisories that are only patched in 7.18.3+:
These are already public advisories (not a new disclosure), flagged here for tracking, not reported as a fresh vulnerability.
The blocker: this is a semver-major bump (v6 → v7), and the app still uses the legacy v6 API (BrowserRouter / Routes / Route in src/app.js). A version-only bump risks breaking routing, so it needs a real migration pass rather than a dependabot-style patch.
While investigating, it looks like src/ (app.js, components/, etc.) may itself be dead code — a leftover from the pre-ui-redesign webpack-based React app:
- Nothing in the current Next.js
app/ router imports from src/.
- No test references it.
- It isn't part of the
next build output.
src/ is the only reason react-router-dom is a direct dependency at all — the live app doesn't route through it. If src/ is confirmed unused and removed, react-router-dom (and this advisory) can likely be dropped from package.json entirely, which would resolve this without a v7 migration.
Expected outcome: either (a) confirm src/ is dead, delete it, and drop react-router-dom, or (b) if src/ is still needed for some reason, migrate it to react-router-dom v7 to clear the advisories.
Reproduction
- Run
npm ls react-router-dom --all on ui-redesign — shows react-router-dom@6.30.6 as a direct dependency.
- Run
npm audit — reports the two advisories above against react-router-dom/react-router, both listing a fix only via 7.18.3 (isSemVerMajor: true).
- Search the codebase for consumers:
grep -rn "from 'react-router-dom'" — only hits are in src/app.js, src/components/app.js, src/components/hero.js. None of these are imported from the Next.js app/ directory, any test file, or referenced in next build output.
Not consistently reproducible as a runtime bug — this is a static dependency/dead-code finding from an npm audit + npm ls + import-graph review, not an observed failure.
Environment
- Version of this library used:
react-router-dom@6.30.6
- Version of the platform or framework used, if applicable: Next.js
16.3.5 (App Router), Node.js >=22.0.0
- Other relevant versions (language, server software, OS, browser): TypeScript
5.9.3, npm (lockfileVersion per package-lock.json)
- Other modules/plugins/libraries that might be involved:
react@19.2.0, react-dom@19.2.0 — note src/app.js still calls the legacy ReactDOM.render API alongside react-router-dom v6, another sign this tree predates the React 19 / App Router migration
Description
react-router-domis pinned at6.30.6and has two remaining moderate-severity advisories that are only patched in7.18.3+:<Link>/useNavigate(CVE-2025-68470 bypass) — GHSA-wrjc-x8rr-h8h6deserializeErrors()in SSR hydration — GHSA-337j-9hxr-rhxgThese are already public advisories (not a new disclosure), flagged here for tracking, not reported as a fresh vulnerability.
The blocker: this is a semver-major bump (v6 → v7), and the app still uses the legacy v6 API (
BrowserRouter/Routes/Routeinsrc/app.js). A version-only bump risks breaking routing, so it needs a real migration pass rather than a dependabot-style patch.While investigating, it looks like
src/(app.js,components/, etc.) may itself be dead code — a leftover from the pre-ui-redesignwebpack-based React app:app/router imports fromsrc/.next buildoutput.src/is the only reasonreact-router-domis a direct dependency at all — the live app doesn't route through it. Ifsrc/is confirmed unused and removed,react-router-dom(and this advisory) can likely be dropped frompackage.jsonentirely, which would resolve this without a v7 migration.Expected outcome: either (a) confirm
src/is dead, delete it, and dropreact-router-dom, or (b) ifsrc/is still needed for some reason, migrate it toreact-router-domv7 to clear the advisories.Reproduction
npm ls react-router-dom --allonui-redesign— showsreact-router-dom@6.30.6as a direct dependency.npm audit— reports the two advisories above againstreact-router-dom/react-router, both listing a fix only via7.18.3(isSemVerMajor: true).grep -rn "from 'react-router-dom'"— only hits are insrc/app.js,src/components/app.js,src/components/hero.js. None of these are imported from the Next.jsapp/directory, any test file, or referenced innext buildoutput.Not consistently reproducible as a runtime bug — this is a static dependency/dead-code finding from an
npm audit+npm ls+ import-graph review, not an observed failure.Environment
react-router-dom@6.30.616.3.5(App Router), Node.js>=22.0.05.9.3, npm (lockfileVersion perpackage-lock.json)react@19.2.0,react-dom@19.2.0— notesrc/app.jsstill calls the legacyReactDOM.renderAPI alongsidereact-router-domv6, another sign this tree predates the React 19 / App Router migration