Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-h5cw-625j-3rxh | React Router has CSRF issue in Action/Server Action Request Processing |
Thu, 05 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shopify
Shopify react-router Shopify remix-run\/react |
|
| CPEs | cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:* cpe:2.3:a:shopify:remix-run\/react:*:*:*:*:*:node.js:*:* |
|
| Vendors & Products |
Shopify
Shopify react-router Shopify remix-run\/react |
Tue, 13 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 12 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 10 Jan 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using server-side route action handlers in Framework Mode, or when using React Server Actions in the new unstable RSC modes. There is no impact if Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>) is being used. This issue has been patched in @remix-run/server-runtime version 2.17.3 and react-router version 7.12.0. | |
| Title | React Router has CSRF issue in Action/Server Action Request Processing | |
| Weaknesses | CWE-346 CWE-352 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-12T18:09:39.441Z
Reserved: 2026-01-05T22:30:38.718Z
Link: CVE-2026-22030
Updated: 2026-01-12T18:09:36.760Z
Status : Analyzed
Published: 2026-01-10T03:15:49.067
Modified: 2026-02-05T20:51:29.483
Link: CVE-2026-22030
OpenCVE Enrichment
Updated: 2026-04-18T16:45:05Z
Github GHSA