Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 npm

React Router has CSRF issue in Action/Server Action Request Processing

GHSA-h5cw-625j-3rxh · CVE-2026-22030

Published · Modified

Description

React Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using server-side route action handlers in Framework Mode, or when using React Server Actions in the new unstable RSC modes.

[!NOTE]
This does not impact your application if you are using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>).

Ready to move

Start Securing

Free, no credit card | First findings in minutes