Skip to content

RSC Mode CSRF Bypass Allows Action Execution Before 400 Response

Moderate
brophdawg11 published GHSA-qwww-vcr4-c8h2 Jul 22, 2026

Package

npm react-router (npm)

Affected versions

>=7.12.0, <8.3.0

Patched versions

>=8.3.0

Description

This is a follow up to CVE-2026-22030 to address related CSRF flows in unstable RSC code paths.

Note

This only affects your application if you are using the unstable RSC APIs

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs

Credits