HIGHCVSS 7.1
GHSA-qwww-vcr4-c8h2
React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
Summary
This is a follow up to CVE-2026-22030 to address related CSRF flows in unstable RSC code paths. > [!NOTE] > This only affects your application if you are using the unstable RSC APIs
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| npm | react-router | — | 8.3.0 |
Remediation: Upgrade to 8.3.0 or later.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.