@shopify/shopify-app-react-router is vulnerable to Improper Verification of Cryptographic Signature
59
Medium Risk
The app proxy authentication flow in @shopify/shopify-app-react-router verifies a Shopify-signed request by validating an HMAC over the forwarded query parameters. Before the fix, the validation flattened the query string in a way that mishandled repeated parameters, so duplicated security parameters such as signature, shop, or timestamp could desynchronize the value used for signature verification from the value the application later reads. This gap lets a tampered app proxy request pass HMAC validation while carrying externally influenced parameter values, undermining the request's authenticity. The fix consumes structured URL search parameters and rejects repeated security parameters while still preserving repeated application query parameters.
You are affected if you are using a version that falls within the vulnerable range and your app authenticates Shopify app proxy requests.
@shopify/shopify-app-react-router is vulnerable to Improper Verification of Cryptographic Signature in versions 0.1.0 - 1.2.1.
Upgrade the @shopify/shopify-app-react-router library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant