Feed/CVE-2026-53667
CVE-2026-53667MEDIUMCVSS 6.9

React Router: RSCErrorHandler Missing Protocol Validation (XSS)

Published Jul 23, 2026·Updated Aug 3, 2026

NVD Description

This is a follow up to https://github.com/remix-run/react-router/security/advisories/GHSA-8646-j5j9-6r62. React Router was alerted of a code path in the (unstable) RSC error handling path in which redirects from untrusted sources could still result in an XSS vector via attacker-supplied redirect targets > [!NOTE] > This only affects your application if you are using the unstable RSC APIs

Affected Packages (1)

react-routerNPM
From 7.11.0
Fixed in 7.18.0

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free