Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-84g9-w2xq-vcv6 | React Router: Potential CSRF via PUT/PATCH/DELETE document requests |
Wed, 24 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 22 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Remix-run
Remix-run react-router Remix-run server-runtime |
|
| Vendors & Products |
Remix-run
Remix-run react-router Remix-run server-runtime |
Mon, 22 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were bypassed on PUT/PATCH/DELETE requests. This is a low severity vulnerability because modern browser protections (CORS preflight, SameSite cookies) already block the cross-origin attack vectors that this missing CSRF check would otherwise gate. This vulnerability is fixed in 7.15.1. | |
| Title | React Router: `handleDocumentRequest` CSRF check covers `POST` only; PUT/PATCH/DELETE bypass | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-22T19:52:50.287Z
Reserved: 2026-06-09T20:50:36.877Z
Link: CVE-2026-53663
Updated: 2026-06-22T19:52:43.823Z
No data.
OpenCVE Enrichment
Updated: 2026-06-22T21:15:04Z
Github GHSA