Skip to content

[GHSA-qwww-vcr4-c8h2] React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response - #9022

Closed
acastlesibm wants to merge 1 commit into
github:acastlesibm/advisory-improvement-9022from
acastlesibm:patch-2
Closed

[GHSA-qwww-vcr4-c8h2] React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response#9022
acastlesibm wants to merge 1 commit into
github:acastlesibm/advisory-improvement-9022from
acastlesibm:patch-2

Conversation

@acastlesibm

Copy link
Copy Markdown

Summary

Updates advisory GHSA-qwww-vcr4-c8h2 for react-router to include the complete set of affected version ranges and their corresponding fixes.

The advisory previously only captured the fix for the 8.x line (8.3.0) but was missing the fix entry for 7.x (7.18.2) and the introduction boundary for the 8.x range (8.0.0), leaving users on react-router@7.12.0–7.18.1 without a clear remediation path.

Changes

  • Add fixed: 7.18.2 for the >= 7.12.0 range
  • Add introduced boundary 8.0.0 for the 8.x range (already had fixed: 8.3.0)

Advisory details

Field Value
ID GHSA-qwww-vcr4-c8h2
Package react-router (npm)
Severity Medium (CVSS v4 4.0)
Summary RSC Mode CSRF Bypass — allows action execution before 400 response
Follow-up to CVE-2026-22030
Reference GHSA-qwww-vcr4-c8h2

Added fixed versions for ecosystem events and updated URLs.
@github-actions
github-actions Bot changed the base branch from main to acastlesibm/advisory-improvement-9022 August 7, 2026 10:00
@acastlesibm acastlesibm closed this Aug 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant