[GHSA-qwww-vcr4-c8h2] React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response - #8868
Conversation
|
Hi there @brophdawg11! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
There was a problem hiding this comment.
Pull request overview
Updates React Router advisory ranges for patched v7 and v8 releases.
Changes:
- Adds separate affected ranges for v7 and v8.
- Records fixed versions and last-known affected ranges.
Comments suppressed due to low confidence (1)
advisories/github-reviewed/2026/07/GHSA-qwww-vcr4-c8h2/GHSA-qwww-vcr4-c8h2.json:51
- As with the v7 range, an OSV
fixedevent must contain the exact boundary version rather than a comparator expression.">= 8.3.0"is not a valid package version and may prevent consumers from closing this affected interval correctly.
"fixed": ">= 8.3.0"
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| }, | ||
| { | ||
| "fixed": "8.3.0" | ||
| "fixed": ">= 7.18.2" |
Updates
Comments
We backported the fix to React Router v7, so the ranges need to be updated: