Summary
React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
Advisory details
This is a follow up to CVE-2026-22030 to address related CSRF flows in unstable RSC code paths.
[!NOTE] This only affects your application if you are using the unstable RSC APIs
References
- https://github.com/advisories/GHSA-qwww-vcr4-c8h2
- https://github.com/remix-run/react-router/security/advisories/GHSA-qwww-vcr4-c8h2
- https://github.com/remix-run/react-router/commit/7a71c728ad116bd78699a258b2014ce9585729f5
- https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v830
- https://github.com/remix-run/react-router/releases/tag/react-router@8.3.0
- http://github.com/remix-run/react-router/pull/15311
Related vulnerabilities
All Supply chain →- HIGHCVE-2026-73222
Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)
- HIGHCVE-2026-73292
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
- MEDIUMCVE-2026-81890
elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections
- HIGHCVE-2026-19418
TYPO3 CMS - Broken Access Control in Backend and Install Tool
- MEDIUMCVE-2026-81888
@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking
- HIGHCVE-2026-55532
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server