← Vulnerability feed

Vulnerability record · CVE-2026-53667 · published 27 July 2026

CVE-2026-53667: Shopify react-router cross-site scripting vulnerability

Shopify · React Router

React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This issue has been fixed in version 7.18.0.

6.1 CVSS 3.1 Medium EPSS 0.36% · top 73.3% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References
3 Aug 2026Last modified by NVD

Description

React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This issue has been fixed in version 7.18.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-53667 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2026-55685Shopify react-router uncontrolled resource consumption vulnerabilityReact Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests t…EPSS 0.71%8.2CVE-2026-21884Shopify react-router cross-site scripting vulnerabilityReact Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in…EPSS 0.54%8.1CVE-2026-42211Shopify react-router deserialization of untrusted data vulnerabilityReact Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unaut…EPSS 0.62%7.6CVE-2025-59057Shopify react-router cross-site scripting vulnerabilityReact Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerab…EPSS 0.51%7.5CVE-2026-42342Shopify react-router uncontrolled resource consumption vulnerabilityReact Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime,…EPSS 0.46%7.5CVE-2026-34077Shopify react-router allocation without limits vulnerabilityReact Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is…EPSS 0.45%6.9CVE-2026-53668Shopify react-router cross-site scripting vulnerabilityReact Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable…EPSS 0.34%6.6CVE-2026-40181Shopify react-router open redirect vulnerabilityReact Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigg…EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2026-53667), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.