CVE-2026-53666

MEDIUM CVSS 3.1: 6.1 EPSS 0.41%
Updated Aug 03, 2026
Shopify
Parameter Value
CVSS 6.1 (MEDIUM)
Affected Versions 6.4.0 — 7.18.0
Fixed In 7.18.0
Type CWE-470
Vendor Shopify
Public PoC No

React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker to trigger unexpected constructor execution on the client, which would in turn trigger an outbound network request. This is only possible with very specific (and unlikely) application-layer code.

Note that this does not impact an application if it is using Declarative Mode. It only impacts Framework Mode and Data Mode applications that perform manual SSR/hydration. This issue has been fixed in version 7.18.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Shopify React-Router
cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*
6.4.0 7.18.0