{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ashopifyreact-routernode.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*","cpe:2.3:a:shopify:remix-run\\/react:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":6.5,"id":"CVE-2026-22030"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["react-router (\u003e= 7.12.0, \u003c 8.3.0)"],"_cs_severities":["medium"],"_cs_tags":["react","router","csrf","web-application","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Remix"],"content_html":"\u003cp\u003eA Cross-Site Request Forgery (CSRF) bypass vulnerability, identified as GHSA-qwww-vcr4-c8h2, has been discovered in specific versions of the React Router library (\u003ccode\u003enpm/react-router\u003c/code\u003e). This flaw, affecting versions greater than or equal to 7.12.0 and less than 8.3.0, specifically impacts applications that utilize the unstable React Server Components (RSC) APIs. This is a follow-up to a previously addressed related CSRF flow (CVE-2026-22030). An attacker can leverage this vulnerability to execute unauthorized actions within the context of an authenticated user's session. The issue allows these actions to be performed even before an expected 400 response would typically halt such attempts. Organizations using React Router with RSC APIs are at risk, as successful exploitation could lead to unauthorized data modification or other integrity compromises.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of the React Router CSRF bypass vulnerability leads to a high integrity impact on affected applications. Attackers can trick authenticated users into performing unintended actions within the application. This could result in unauthorized data manipulation, configuration changes, or other actions that compromise the trustworthiness and veracity of information managed by the vulnerable system. While the advisory does not specify observed victims or targeted sectors, any web application using the affected React Router versions with unstable RSC APIs is susceptible to this integrity compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade \u003ccode\u003enpm/react-router\u003c/code\u003e to version \u003ccode\u003e8.3.0\u003c/code\u003e or later, as referenced in the GitHub advisory GHSA-qwww-vcr4-c8h2, to remediate the Cross-Site Request Forgery (CSRF) bypass vulnerability.\u003c/li\u003e\n\u003cli\u003eReview applications utilizing React Router's unstable RSC APIs to understand potential exposure and verify successful patching.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T16:51:35Z","date_published":"2026-07-24T16:51:35Z","id":"https://feed.craftedsignal.io/briefs/2026-07-react-router-csrf-bypass/","summary":"A high-severity Cross-Site Request Forgery (CSRF) bypass vulnerability in React Router's unstable React Server Components (RSC) APIs allows for action execution before a 400 response, impacting applications utilizing these specific APIs.","title":"React Router RSC Mode CSRF Bypass","url":"https://feed.craftedsignal.io/briefs/2026-07-react-router-csrf-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:shopify:react-Router:*:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}