PT-2026-64212 · Unknown · React Router
CVE-2026-53666
·
Published
2026-07-23
·
Updated
2026-08-11
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
React Router versions 6.4.0 through 7.17.0
Description
In Framework Mode and Data Mode applications performing manual SSR (Server-Side Rendering), a flaw exists where attacker-supplied input can overwrite specific aspects of errors caught during the SSR process. This can lead to unexpected constructor execution on the client side, resulting in unauthorized outbound network requests. This issue requires very specific application-layer code to be exploitable and does not affect applications using Declarative Mode.
Recommendations
Update to version 7.18.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
React Router