<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>React-Router (&gt;= 7.12.0, &lt; 8.3.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/react-router--7.12.0--8.3.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 24 Jul 2026 16:51:35 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/react-router--7.12.0--8.3.0/feed.xml" rel="self" type="application/rss+xml"/><item><title>React Router RSC Mode CSRF Bypass</title><link>https://feed.craftedsignal.io/briefs/2026-07-react-router-csrf-bypass/</link><pubDate>Fri, 24 Jul 2026 16:51:35 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-react-router-csrf-bypass/</guid><description>A high-severity Cross-Site Request Forgery (CSRF) bypass vulnerability in React Router's unstable React Server Components (RSC) APIs allows for action execution before a 400 response, impacting applications utilizing these specific APIs.</description><content:encoded><![CDATA[<p>A Cross-Site Request Forgery (CSRF) bypass vulnerability, identified as GHSA-qwww-vcr4-c8h2, has been discovered in specific versions of the React Router library (<code>npm/react-router</code>). This flaw, affecting versions greater than or equal to 7.12.0 and less than 8.3.0, specifically impacts applications that utilize the unstable React Server Components (RSC) APIs. This is a follow-up to a previously addressed related CSRF flow (CVE-2026-22030). An attacker can leverage this vulnerability to execute unauthorized actions within the context of an authenticated user's session. The issue allows these actions to be performed even before an expected 400 response would typically halt such attempts. Organizations using React Router with RSC APIs are at risk, as successful exploitation could lead to unauthorized data modification or other integrity compromises.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of the React Router CSRF bypass vulnerability leads to a high integrity impact on affected applications. Attackers can trick authenticated users into performing unintended actions within the application. This could result in unauthorized data manipulation, configuration changes, or other actions that compromise the trustworthiness and veracity of information managed by the vulnerable system. While the advisory does not specify observed victims or targeted sectors, any web application using the affected React Router versions with unstable RSC APIs is susceptible to this integrity compromise.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately upgrade <code>npm/react-router</code> to version <code>8.3.0</code> or later, as referenced in the GitHub advisory GHSA-qwww-vcr4-c8h2, to remediate the Cross-Site Request Forgery (CSRF) bypass vulnerability.</li>
<li>Review applications utilizing React Router's unstable RSC APIs to understand potential exposure and verify successful patching.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>react</category><category>router</category><category>csrf</category><category>web-application</category><category>vulnerability</category></item></channel></rss>