Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.1

CVE-2026-53667: React Router RSC Error Handler: Unsecured Redirects

CVE-2026-53667 · published 22 days ago
Summary

Using React Router's unstable RSC APIs, an attacker could trick your application into redirecting users to malicious websites, potentially allowing the attacker to steal sensitive information or take control of the user's session. This only affects applications that use the unstable RSC APIs. To fix this, update to the latest version of React Router.

What to do
  • Update GitHub Actions react-router to version 7.18.0.
  • Update react-router to version 7.18.0.
  • Update shopify react-router to version 7.18.0 or later.
Affected software
Ecosystem VendorProductAffected versions
npm GitHub Actions react-router >= 7.11.0, < 7.18.0
Fix: upgrade to 7.18.0
remix-run react-router >= 7.11.0, < 7.18.0
npm react-router >= 7.11.0, < 7.18.0
Fix: upgrade to 7.18.0
shopify react-router >= 7.11.0, < 7.18.0
cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*
Original advisory text
React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up t...
React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This issue has been fixed in version 7.18.0.
Severity
6.1 Medium
CVSS 3.1: 6.9 (GHSA)
Exploitation
EPSS <1%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published27 Jul 2026
Updated15 Aug 2026
First seen23 Jul 2026
Sources
CVE-2026-53667 · MITRE
Monitor software like this
Free during beta