Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-53667

Опубликовано: 27 июл. 2026
Источник: nvd
CVSS3: 6.9
EPSS Низкий

Описание

React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This issue has been fixed in version 7.18.0.

EPSS

Процентиль: 28%
0.00354
Низкий

6.9 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.9
redhat
8 дней назад

A flaw was found in React Router. The RSCErrorHandler component, used in applications leveraging unstable React Server Components (RSC) Application Programming Interfaces (APIs), is missing crucial protocol validation. This vulnerability allows an attacker to redirect users to untrusted external websites. Such redirects can lead to information disclosure or facilitate phishing attacks, potentially exposing sensitive user data.

CVSS3: 6.9
github
12 дней назад

React Router: RSCErrorHandler Missing Protocol Validation (XSS)

EPSS

Процентиль: 28%
0.00354
Низкий

6.9 Medium

CVSS3

Дефекты

CWE-79