MEDIUM 6.5 npm
React Router has CSRF issue in Action/Server Action Request Processing
GHSA-h5cw-625j-3rxh · CVE-2026-22030
Published · Modified
Description
React Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using server-side route action handlers in Framework Mode, or when using React Server Actions in the new unstable RSC modes.
[!NOTE]
This does not impact your application if you are using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>).
Ready to move
Start Securing
Free, no credit card | First findings in minutes