Answer in brief
CVE-2026-53663 records a Low severity (CVSS 3.1) csrf vulnerability in React Router: Potential CSRF via PUT/PATCH/DELETE document requests. The source record does not mark it as known exploited. 2 affected packages are mapped in the feed.
Answer in brief
CVE-2026-53663 records a Low severity (CVSS 3.1) csrf vulnerability in React Router: Potential CSRF via PUT/PATCH/DELETE document requests. The source record does not mark it as known exploited. 2 affected packages are mapped in the feed.
Update react-router to 7.15.1; @remix-run/server-runtime to 2.17.5 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCSRF describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-53663 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| react-routernpm | >=7.12.0,<7.15.1 | 7.15.1 |
| @remix-run/server-runtimenpm | >=2.17.3,<2.17.5 | 2.17.5 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Certain CSRF checks in React Router v7 [Framework Mode]() were insufficient and run on POST requests, but were bypassed on PUT/PATCH/DELETE requests. This is a low severity vulnerability because modern browser protections (CORS preflight, SameSite cookies) already block the cross-origin attack vectors that this missing CSRF check would otherwise gate. > [!NOTE] > This does not impact your React Router application if you are using [Declarative Mode](https://reactrouter.com/start/modes#framework) (`<BrowserRouter>`) or [Data Mode](https://reactrouter.com/start/modes#data) (`createBrowserRouter`/`<RouterProvider>`).
Reported by GitHub Security Advisories (ghsa).
CVE-2026-53663 records a Low severity (CVSS 3.1) csrf vulnerability in React Router: Potential CSRF via PUT/PATCH/DELETE document requests. The source record does not mark it as known exploited. 2 affected packages are mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for react-router, @remix-run/server-runtime.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate react-router to 7.15.1; @remix-run/server-runtime to 2.17.5 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCSRF describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-53663 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| react-routernpm | >=7.12.0,<7.15.1 | 7.15.1 |
| @remix-run/server-runtimenpm | >=2.17.3,<2.17.5 | 2.17.5 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Certain CSRF checks in React Router v7 [Framework Mode]() were insufficient and run on POST requests, but were bypassed on PUT/PATCH/DELETE requests. This is a low severity vulnerability because modern browser protections (CORS preflight, SameSite cookies) already block the cross-origin attack vectors that this missing CSRF check would otherwise gate. > [!NOTE] > This does not impact your React Router application if you are using [Declarative Mode](https://reactrouter.com/start/modes#framework) (`<BrowserRouter>`) or [Data Mode](https://reactrouter.com/start/modes#data) (`createBrowserRouter`/`<RouterProvider>`).
Reported by GitHub Security Advisories (ghsa).
CVE-2026-53663 records a Low severity (CVSS 3.1) csrf vulnerability in React Router: Potential CSRF via PUT/PATCH/DELETE document requests. The source record does not mark it as known exploited. 2 affected packages are mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for react-router, @remix-run/server-runtime.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard