PT-2026-64213 · Unknown · React Router

CVE-2026-53667

·

Published

2026-07-23

·

Updated

2026-08-11

CVSS v3.1

6.9

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions React Router versions 7.11.0 through 7.17.0
Description The RSCErrorHandler lacks protocol validation, which allows redirects from untrusted sources. This can lead to a Cross-Site Scripting (XSS) vector—a technique where malicious scripts are injected into trusted websites—via attacker-supplied redirect targets. This issue only affects applications utilizing the unstable RSC (React Server Components) APIs.
Recommendations Update React Router to version 7.18.0. Restrict the use of unstable RSC APIs as a temporary mitigation measure.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53667
GHSA-H8FP-F39C-Q6MH

Affected Products

React Router