Junglewise Threat Intelligence

CVE-2026-53666: remix-run React Router unsafe reflection in SSR hydration

CVE-2026-53666 · Severity: medium · CVSS 6.1 · Published 2026-07-27

Vendors: Remix.

Executive brief

React Router is a popular JavaScript routing library used in web applications, particularly those using server-side rendering (SSR). An attacker can exploit a deserialization flaw to execute arbitrary constructors on the client side when specific application code patterns are present, potentially triggering unintended network requests. This vulnerability only affects Framework Mode and Data Mode applications performing manual SSR/hydration; Declarative Mode is unaffected.

Technical details

The vulnerability exists in React Router's SSR hydration error deserialization mechanism, specifically in the deserializeErrors() function. An attacker who can control application-layer error handling code can inject arbitrary constructor execution during the hydration phase on the client side. This is a deserialization-based code execution issue (CWE-470) that requires specific and unlikely application code patterns to be exploitable. The attack vector is network-based with no privileges required but does require user interaction (UI rendering). The root cause was addressed in version 7.18.0 by switching from custom error serialization to turbo-stream encoding, which prevents constructor injection. Patched versions are available in react-router >= 7.18.0.

Affected products

  • Remix react-router >=6.4.0, <7.18.0

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: patched: Fix released in react-router 7.18.0

References