MEDIUM6.5
GHSA-h5cw-625j-3rxh
React Router has CSRF issue in Action/Server Action Request Processing
Quick fix
GHSA-h5cw-625j-3rxh — react-router: upgrade to the fixed version with the command below.
npm install react-router@7.12.0Details
React Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using server-side route `action` handlers in [Framework Mode](https://reactrouter.com/start/modes#framework), or when using React Server Actions in the new unstable RSC modes.
> [!NOTE] > This does not impact your application if you are using [Declarative Mode](https://reactrouter.com/start/modes#declarative) (`<BrowserRouter>`) or [Data Mode](https://reactrouter.com/start/modes#data) (`createBrowserRouter`/`<RouterProvider>`).
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/@remix-run/server-runtime
Introduced in:
0Fixed in: 2.17.3Fix
npm install @remix-run/server-runtime@2.17.3