Arbitrary client-side constructor injection in React Router SSR Hydration (CVE-2026-5366)
Security Advisory
GHSA-337f-9hr-rhxg
Medium
React Router
Affected:
- react-router >= 6.4.0, < 7.18.0
Fixed in:
- react-router >= 7.18.0
Referenced CVEs:
CVE-2026-53666 · 6.1
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.