Junglewise Threat Intelligence

React Router CSRF bypass in RSC mode action execution

Severity: high · CVSS 7.1 · Published 2026-07-24

Technologies: Remix-Run React Router.

Executive brief

A security vulnerability exists in React Router's experimental React Server Components (RSC) feature. This flaw could allow an attacker to trick a user's browser into performing unauthorized actions on a website without the user's consent. This could lead to unauthorized data modifications or account changes if the application uses these specific unstable features.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability (CWE-352) exists in React Router when using unstable React Server Components (RSC) APIs. The flaw allows an attacker to bypass CSRF protections and execute server-side actions before the system returns a 400 Bad Request response. This is a follow-up to a previous vulnerability (CVE-2026-22030) and specifically targets RSC code paths. Exploitation requires a victim to interact with a malicious link or site while authenticated to the vulnerable application. The issue is resolved in version 8.3.0.

Affected products

  • remix-run react-router >= 7.12.0, < 8.3.0

Timeline

  • 2026-07-22: patched: Fix released in version 8.3.0
  • 2026-07-24: advisory: GitHub Advisory published

References