CVE-2026-53667Medium· 6.9▾ SunlitReact Router: RSCErrorHandler Missing Protocol Validation (XSS)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 38 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 28.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.4%
This is a follow up to https://github.com/remix-run/react-router/security/advisories/GHSA-8646-j5j9-6r62. React Router was alerted of a code path in the (unstable) RSC error handling path in which redirects from untrusted sources could still result in an XSS vector via attacker-supplied redirect targets
[!NOTE] This only affects your application if you are using the unstable RSC APIs
react-router >= 7.11.0, < 7.18.0Upgrade to a patched release:
react-router 7.18.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53668Medium· 6.9React Router: Open redirect leading to XSS
CVE-2026-53666Medium· 6.1React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
CVE-2026-53669MediumReact Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
CVE-2026-33244Medium· 5.4React Router has stored XSS via unescaped Location header in prerendered redirect HTML
CVE-2026-21884High· 8.2React Router is a router for React
CVE-2025-59057High· 7.6React Router is a router for React