Security Digest: January 8, 2026 - 10 Critical Vulnerabilities

Today's security landscape reveals 10 critical vulnerabilities impacting major frameworks such as React Router, Ghost, and NiceGUI. Immediate patching and mitigation are required to prevent potential exploits.

· 5 min read

Urgent: 10 Critical Vulnerabilities Discovered Today

Executive Summary

Today's security landscape reveals 10 critical vulnerabilities impacting major frameworks such as React Router, Ghost, and NiceGUI. Immediate patching and mitigation are required to prevent potential exploits that could lead to serious security breaches, including unauthorized data access and cross-site scripting (XSS) attacks.

Critical Vulnerabilities

  • CVE-2025-61686: Unsigned Cookie Session Hijacking

    Impact: Allows unauthorized file access.
    Affected Systems: npm @react-router/node, @remix-run/node, @remix-run/deno.
    Immediate Action: Implement cookie signing immediately.
    Mitigation: Update to the latest secured version and ensure all cookies are signed.

  • CVE-2026-22256: Reflected XSS in Salvo

    Impact: JavaScript execution leading to account takeover.
    Affected Systems: Rust Salvo.
    Immediate Action: Sanitize all HTML output.
    Mitigation: Apply security patches from the vendor.

  • CVE-2026-22257: XSS in Salvo File Uploads

    Impact: Execution of arbitrary JavaScript.
    Affected Systems: Rust Salvo.
    Immediate Action: Validate file names and paths.
    Mitigation: Upgrade to a patched version.

  • CVE-2026-21884: XSS in React Router's ScrollRestoration

    Impact: Arbitrary JavaScript execution during SSR.
    Affected Systems: npm react-router, @remix-run/react.
    Immediate Action: Disable SSR or update to the latest version.
    Mitigation: Use alternative routing modes.

  • CVE-2026-22595: Ghost Staff Token Endpoint Exposure

    Impact: Unintended endpoint access.
    Affected Systems: Ghost v5.121.0 to v6.10.3.
    Immediate Action: Update to v5.130.6 or v6.11.0.
    Mitigation: Apply patches provided by Ghost.

  • CVE-2026-22594: Ghost 2FA Bypass

    Impact: Bypass of 2FA for staff users.
    Affected Systems: Ghost v5.105.0 to v6.10.3.
    Immediate Action: Upgrade immediately to v5.130.6 or v6.11.0.
    Mitigation: Enforce strict 2FA verification.

  • CVE-2026-22029: Unsafe Redirects in React Router

    Impact: Unintended JavaScript execution.
    Affected Systems: npm react-router, @remix-run/router.
    Immediate Action: Review and sanitize redirect paths.
    Mitigation: Use secure redirect mechanisms.

  • CVE-2025-59057: XSS in React Router's Meta API

    Impact: JavaScript execution via `script:ld+json`.
    Affected Systems: npm react-router, @remix-run/react.
    Immediate Action: Validate content used in meta tags.
    Mitigation: Switch to secure framework modes.

  • CVE-2026-22589: IDOR in Spree Core

    Impact: Unauthenticated access to guest data.
    Affected Systems: rubygems spree_core.
    Immediate Action: Implement proper authorization checks.
    Mitigation: Update to the latest version that addresses this issue.

  • CVE-2026-21873: XSS in NiceGUI's ui.sub_pages

    Impact: JavaScript execution via URL manipulation.
    Affected Systems: pip nicegui.
    Immediate Action: Block iframe embedding.
    Mitigation: Apply security headers to prevent iframe use.

What to Do Now

  1. Patch all affected systems immediately with the latest updates from vendors.
  2. Review and enhance input validation and output sanitization practices.
  3. Monitor application logs for suspicious activity related to these vulnerabilities.

Related Resources

Keep reading