Executive brief
A security vulnerability exists in React Router's experimental React Server Components (RSC) feature. This flaw could allow an attacker to trick a user's browser into performing unauthorized actions on a website without the user's consent. This could lead to unauthorized data modifications or account changes if the application uses these specific unstable features.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability (CWE-352) exists in React Router when using unstable React Server Components (RSC) APIs. The flaw allows an attacker to bypass CSRF protections and execute server-side actions before the system returns a 400 Bad Request response. This is a follow-up to a previous vulnerability (CVE-2026-22030) and specifically targets RSC code paths. Exploitation requires a victim to interact with a malicious link or site while authenticated to the vulnerable application. The issue is resolved in version 8.3.0.
Affected products
- remix-run react-router >= 7.12.0, < 8.3.0
Timeline
- 2026-07-22: patched: Fix released in version 8.3.0
- 2026-07-24: advisory: GitHub Advisory published