Protocol Validation Flaw in React Router by Remix Run
CVE-2026-53667

6.9MEDIUM

Key Information:

Vendor

Remix-run

Vendor
CVE Published:
27 July 2026

What is CVE-2026-53667?

A vulnerability has been identified in React Router versions 7.11.0 through 7.17.0, where the RSCErrorHandler fails to properly validate protocols. This oversight can enable malicious redirects from untrusted sources, potentially compromising application security. The issue specifically arises when applications utilize the unstable RSC APIs. The vulnerability is addressed in version 7.18.0, which implements the necessary protocol validation to enhance security.

Affected Version(s)

react-router >= 7.11.0, < 7.18.0

References

CVSS V3.1

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.