PT-2026-64212 · Unknown · React Router

CVE-2026-53666

·

Published

2026-07-23

·

Updated

2026-08-11

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions React Router versions 6.4.0 through 7.17.0
Description In Framework Mode and Data Mode applications performing manual SSR (Server-Side Rendering), a flaw exists where attacker-supplied input can overwrite specific aspects of errors caught during the SSR process. This can lead to unexpected constructor execution on the client side, resulting in unauthorized outbound network requests. This issue requires very specific application-layer code to be exploitable and does not affect applications using Declarative Mode.
Recommendations Update to version 7.18.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53666
GHSA-337J-9HXR-RHXG

Affected Products

React Router