Vulnerabilities/

React Router: Potential CSRF via PUT/PATCH/DELETE document requests

Severity:
Low

Description

Certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were bypassed on PUT/PATCH/DELETE requests.

Recommendation

Update the @remix-run/server-runtime package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@remix-run/server-runtime
Anything's wrong? Let us know Last updated on June 15, 2026