Even Shopify's own HMAC check had a bug — go update
Shopify disclosed GHSA-3h8r-q86m-44c7: an HMAC validation bug in App Proxy request verification across @shopify/shopify-api and the official app templates. Moderate, no known exploitation, one fix — upgrade.
On August 10, Shopify published a security advisory — GHSA-3h8r-q86m-44c7 — for the shopify-app-js packages. It’s rated Moderate, has no CVE, and there’s no indication anyone has exploited it in the wild.
So: not an incident. But if you build on Shopify’s official Node packages — and most Shopify apps do — it’s a this-week item, not a someday item.
The bug
Shopify App Proxy lets a storefront route requests through Shopify to your app. To prove those requests actually came from Shopify, Shopify signs each one with an HMAC computed from your app’s secret — the exact same trust mechanism as webhooks.
The affected packages had a bug in that HMAC verification. The result: unauthenticated App Proxy requests could slip past validation that was supposed to reject them — giving unauthorized access to App Proxy endpoints that should require a valid Shopify signature.
If you read The Unlocked Webhook, this is the same trust boundary — a signature you must verify — except this time the bug was in Shopify’s own verification code. Which is exactly the point we keep making: getting HMAC verification precisely right is genuinely hard. Even the people who wrote the platform can get a subtle case wrong.
Are you affected?
If you depend on any of these in the vulnerable range — directly, or transitively through one of the app templates — yes:
| Package | Vulnerable range | Fixed from | Recommended |
|---|---|---|---|
@shopify/shopify-api | >=7.6.0 <13.2.0 | 13.2.0 | 14.0.0 |
@shopify/shopify-app-remix | >=1.2.0 <4.2.2 | 4.2.2 | 5.0.0 |
@shopify/shopify-app-express | >2.2.3 <8.0.0 | 8.0.0 | 8.0.0 |
@shopify/shopify-app-react-router | >=0.1.0 <2.0.0 | 2.0.0 | 2.0.0 |
The shopify-api and shopify-app-remix fixes are also available on the older major line (13.2.0 / 4.2.2) if you can’t jump a major right away — but Shopify recommends the latest.
Check what you’re actually running:
npm ls @shopify/shopify-api @shopify/shopify-app-remix \
@shopify/shopify-app-express @shopify/shopify-app-react-router
The fix
There is no workaround — upgrade. Update @shopify/shopify-api plus whichever app template you use:
# adjust to the packages you actually depend on
npm install @shopify/shopify-api@^14.0.0 @shopify/shopify-app-remix@^5.0.0
(pnpm add / yarn add work the same way.)
A few of these are major bumps (shopify-api 14, shopify-app-express 8, shopify-app-remix 5, shopify-app-react-router 2), so skim each package’s changelog for breaking changes and re-run your tests before shipping. And if you hand-rolled your own App Proxy signature check instead of relying on the library, audit it too — verify the HMAC over the raw request and compare in constant time.
Why we’re flagging a “Moderate”
No CVE, no known exploitation, moderate severity — so why the post? Three reasons:
- It lives in the packages a huge slice of the Shopify app ecosystem is built on.
- It’s an auth bypass on a signed endpoint — the failure mode is “requests you thought were verified weren’t.”
- It’s a clean reminder that signature verification is easy to get subtly wrong, and that keeping dependencies current is a security control, not just housekeeping. A Dependabot alert — or an AI security harness in CI — surfaces this the day it drops instead of the day it bites.
Straight from the source
- GHSA-3h8r-q86m-44c7 — the advisory
- Shopify/shopify-app-js — the repo + releases
- Authenticate app proxies — how App Proxy signatures work, if you verify them yourself