Summary

React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response

Advisory details

This is a follow up to CVE-2026-22030 to address related CSRF flows in unstable RSC code paths.

[!NOTE] This only affects your application if you are using the unstable RSC APIs

References