../trash-talk

Aug 11, 2026 #advisory#hmac#app-proxy#dependencies#shopify-app-js

Even Shopify's own HMAC check had a bug — go update

Shopify disclosed GHSA-3h8r-q86m-44c7: an HMAC validation bug in App Proxy request verification across @shopify/shopify-api and the official app templates. Moderate, no known exploitation, one fix — upgrade.

On August 10, Shopify published a security advisory — GHSA-3h8r-q86m-44c7 — for the shopify-app-js packages. It’s rated Moderate, has no CVE, and there’s no indication anyone has exploited it in the wild.

So: not an incident. But if you build on Shopify’s official Node packages — and most Shopify apps do — it’s a this-week item, not a someday item.

The bug

Shopify App Proxy lets a storefront route requests through Shopify to your app. To prove those requests actually came from Shopify, Shopify signs each one with an HMAC computed from your app’s secret — the exact same trust mechanism as webhooks.

The affected packages had a bug in that HMAC verification. The result: unauthenticated App Proxy requests could slip past validation that was supposed to reject them — giving unauthorized access to App Proxy endpoints that should require a valid Shopify signature.

If you read The Unlocked Webhook, this is the same trust boundary — a signature you must verify — except this time the bug was in Shopify’s own verification code. Which is exactly the point we keep making: getting HMAC verification precisely right is genuinely hard. Even the people who wrote the platform can get a subtle case wrong.

Are you affected?

If you depend on any of these in the vulnerable range — directly, or transitively through one of the app templates — yes:

PackageVulnerable rangeFixed fromRecommended
@shopify/shopify-api>=7.6.0 <13.2.013.2.014.0.0
@shopify/shopify-app-remix>=1.2.0 <4.2.24.2.25.0.0
@shopify/shopify-app-express>2.2.3 <8.0.08.0.08.0.0
@shopify/shopify-app-react-router>=0.1.0 <2.0.02.0.02.0.0

The shopify-api and shopify-app-remix fixes are also available on the older major line (13.2.0 / 4.2.2) if you can’t jump a major right away — but Shopify recommends the latest.

Check what you’re actually running:

npm ls @shopify/shopify-api @shopify/shopify-app-remix \
       @shopify/shopify-app-express @shopify/shopify-app-react-router

The fix

There is no workaround — upgrade. Update @shopify/shopify-api plus whichever app template you use:

# adjust to the packages you actually depend on
npm install @shopify/shopify-api@^14.0.0 @shopify/shopify-app-remix@^5.0.0

(pnpm add / yarn add work the same way.)

A few of these are major bumps (shopify-api 14, shopify-app-express 8, shopify-app-remix 5, shopify-app-react-router 2), so skim each package’s changelog for breaking changes and re-run your tests before shipping. And if you hand-rolled your own App Proxy signature check instead of relying on the library, audit it too — verify the HMAC over the raw request and compare in constant time.

Why we’re flagging a “Moderate”

No CVE, no known exploitation, moderate severity — so why the post? Three reasons:

  1. It lives in the packages a huge slice of the Shopify app ecosystem is built on.
  2. It’s an auth bypass on a signed endpoint — the failure mode is “requests you thought were verified weren’t.”
  3. It’s a clean reminder that signature verification is easy to get subtly wrong, and that keeping dependencies current is a security control, not just housekeeping. A Dependabot alert — or an AI security harness in CI — surfaces this the day it drops instead of the day it bites.

Straight from the source