Junglewise Threat Intelligence

React Router CSRF bypass in RSC mode

Severity: medium · CVSS 4 · Published 2026-07-24

Vendors: Remix.

Executive brief

React Router is a JavaScript routing library used to build single-page applications. The RSC (React Server Components) mode includes a CSRF protection mechanism that can be bypassed, allowing an attacker to execute server actions without proper token validation. This could lead to unauthorized state changes or data modification on affected applications using unstable RSC APIs.

Technical details

This vulnerability is a CSRF bypass (CWE-352) in React Router's unstable RSC code paths. The vulnerability allows server actions to be executed before a 400 response is returned, bypassing CSRF protections in place. The issue requires user interaction (e.g., a user visiting a malicious site) and only affects applications using the unstable RSC APIs. An attacker can craft a cross-site request to trigger unintended server actions with the victim's credentials. Patches are available in versions 7.18.2 and 8.3.0.

Affected products

  • Remix React Router 7.12.0 to 7.18.1, 8.0.0 to 8.2.x

Timeline

  • 2026-07-24: disclosed
  • 2026-07-28: patched: Patches released in versions 7.18.2 and 8.3.0

References