Skip to content

fix(deps): react-router-dom ^7.18.2 — RSC-mode CSRF bypass - #154

Merged
coccyx merged 3 commits into
masterfrom
fix/react-router-csrf
Aug 21, 2026
Merged

fix(deps): react-router-dom ^7.18.2 — RSC-mode CSRF bypass#154
coccyx merged 3 commits into
masterfrom
fix/react-router-csrf

Conversation

@coccyx

@coccyx coccyx commented Aug 21, 2026

Copy link
Copy Markdown
Contributor

One-sentence summary: bumps react-router-dom past the high-severity RSC-mode CSRF advisory (Dependabot #11; vulnerable >=7.12.0 <7.18.2, fixed 7.18.2).

This app doesn't use RSC mode, so exposure is theoretical — but it's a one-line range bump. Lockfile regenerated via the Update-lockfile workflow (react-router 7.18.2 resolved; nothing else moved).

🤖 Generated with Claude Code

https://claude.ai/code/session_0158jez4WfWj6ttmaxh3HEbT

coccyx and others added 3 commits August 20, 2026 22:06
…#11)

High-severity advisory: RSC Mode CSRF bypass allows action execution
before the 400 response (react-router >=7.12.0 <7.18.2). This app
doesn't use RSC mode, so exposure is theoretical, but the bump is a
one-liner.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0158jez4WfWj6ttmaxh3HEbT
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedreact-router-dom@​7.18.1 ⏵ 7.18.21001006594 -1100

View full report

@coccyx
coccyx merged commit 882cc24 into master Aug 21, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant