A AegiFlow
HIGHCVSS 7.1

GHSA-qwww-vcr4-c8h2

React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response

Published
2026-07-24
Modified
2026-07-24
Sources
github-advisory

Summary

This is a follow up to CVE-2026-22030 to address related CSRF flows in unstable RSC code paths. > [!NOTE] > This only affects your application if you are using the unstable RSC APIs

Affected packages

EcosystemPackageAffected versionsFixed versions
npmreact-router8.3.0

Remediation: Upgrade to 8.3.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.