[GHSA-qwww-vcr4-c8h2] React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response - #8983
Conversation
|
Hi there @brophdawg11! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
There was a problem hiding this comment.
Pull request overview
Updates the React Router advisory with the v7 backport and supporting references.
Changes:
- Adds v7.18.2 fix metadata.
- Adds backport PR, commit, changelog, and release references.
Suppressed comments (1)
advisories/github-reviewed/2026/07/GHSA-qwww-vcr4-c8h2/GHSA-qwww-vcr4-c8h2.json:35
- This range still marks the fixed
7.18.2release and every later v7 release as affected (and also includes versions before the7.12.0introduction). Remove this contradictory summary and let the corrected OSV events describe the two bounded affected intervals.
"last_known_affected_version_range": "< 8.3.0"
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| }, | ||
| { | ||
| "fixed": "8.3.0" | ||
| "fixed": ">= 7.12.2, >= 8.3.0" |
|
dup of #8868 |
|
@brophdawg11 maybe take #8858? |
Updates
Comments
7.18.2 has the fixes backport and GHSA-qwww-vcr4-c8h2 already updated with both fixed versions.