How to use this reference
The advisory identifies 7.18.0 as patched. Editorial lesson: preserve a narrow, inert contract for errors crossing the server/client boundary, including metadata used to reconstruct them. Review error transport separately from visible error text, and constrain client interpretation to explicitly supported representations. The reviewed advisory does not establish the exact patch implementation.
Before reading
- Server-side rendering and client hydration
- Error serialization and data-versus-behavior boundaries
Context and limits
- CVE-2026-53666. brophdawg11 published the advisory; yoyomiski is credited as reporter. The affected range is at least 6.4.0 and below 7.18.0.
- The maintainer limits applicability to Framework Mode and Data Mode with manual SSR/hydration, excluding Declarative Mode. Do not infer general client code execution, server compromise, or demonstrated data theft from the bounded description.
- The software release page displays June 16 without a year in retrieved text. A full patch-release date is not asserted or substituted for educational-resource chronology.
- No individual bounty is established. Learning prerequisites and generalized review guidance are editorial.
Sources and provenance
- Arbitrary client-side constructor injection via React Router SSR Hydration React Router / Remix · reviewed 2026-10-03
- React Router v7.18.0 release React Router / Remix · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.