← Browse

CVE-2026-53668

Low

No strong exploitation signal.

CVSS base
6.9 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
EPSS — probability of exploitation (30 days)
0.3%
24.9th percentile
CISA KEV
Not listed
Weakness / dates
CWE-79
Published 2026-07-27 · modified 2026-08-03

CVSS breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N

Attack VectorNNetwork
Attack ComplexityHHigh
Privileges RequiredNNone
User InteractionRRequired
ScopeCChanged
ConfidentialityHHigh
IntegrityLLow
AvailabilityNNone

Timeline

Description

React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site or that exploits an XSS vector.This issue has been fixed in version 7.13.0.

Affected

shopify

References

Official: NVD · CVE.org