VYPR
Medium severity6.9OSV Advisory· Published Jul 27, 2026· Updated Aug 3, 2026

CVE-2026-53667

CVE-2026-53667

Description

React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This issue has been fixed in version 7.18.0.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
react-routernpm
>= 7.11.0, < 7.18.07.18.0

Affected products

5

Patches

Vulnerability mechanics

References

6

News mentions

1