GHSA-qwww-vcr4-c8h2HighDisclosed before NVD

React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response

Published
July 24, 2026
Last Modified
August 7, 2026

📋 Description

This is a follow up to CVE-2026-22030 to address related CSRF flows in unstable RSC code paths.

[!NOTE] This only affects your application if you are using the unstable RSC APIs

🎯 Affected products2

  • npm/react-router:>= 7.12.0, < 7.18.2
  • npm/react-router:>= 8.0.0, < 8.3.0

🔗 References (10)