Description
React Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using server-side route action handlers in Framework Mode, or when using React Server Actions in the new unstable RSC modes.
Recommendation
Update the @remix-run/server-runtime package to the latest compatible version. Followings are version details:
- Affected version(s): <= 2.17.2
- Patched version(s): 2.17.3
References
Could your website be exposed too?
SmartScanner can check your website for React Router has CSRF issue in Action/Server Action Request Processing and gives you actionable findings to investigate.
Start a free scanRelated Issues
- React Router: Potential CSRF via PUT/PATCH/DELETE document requests - CVE-2026-53663
- BigSweetPotatoStudio HyperChat has a Server-Side Request Forgery issue - CVE-2026-7223
- @better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints - CVE-2026-53513
- RedwoodSDK has Same-site CSRF through lack of origin validation in its server actions - CVE-2026-42190


