GHSA-qwww-vcr4-c8h2High▾ TwilightReact Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
This is a follow up to CVE-2026-22030 to address related CSRF flows in unstable RSC code paths.
[!NOTE] This only affects your application if you are using the unstable RSC APIs
react-router >= 7.12.0, < 8.3.0Upgrade to a patched release:
react-router 8.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53663Low· 3.1React Router: Potential CSRF via PUT/PATCH/DELETE document requests
CVE-2026-33244Medium· 5.4React Router has stored XSS via unescaped Location header in prerendered redirect HTML
CVE-2026-53666Medium· 6.1React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
CVE-2026-53667Medium· 6.9React Router: RSCErrorHandler Missing Protocol Validation (XSS)
CVE-2026-53668Medium· 6.9React Router: Open redirect leading to XSS
CVE-2026-53669MediumReact Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)