Cross-site request forgery In @remix-run/server-runtime
Description
A cross site request forgery flaw has been discovered in the npm react-router package. React Router is vulnerable to CSRF attacks on document POST requests to UI routes when using server-side route action handlers in Framework Mode, or when using React Server Actions in the new unstable RSC modes.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 2.17.3 | ||
npm | 7.12.0 | ||
rpm rhel9 | - | - |
Aliases
1. 2. 3. 4. 5.
References
1.