Cross-site request forgery in server-runtime - CVE-2026-53663
Published: June 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform cross-site request forgery actions.
The vulnerability exists due to cross-site request forgery in document request handling when processing PUT, PATCH, or DELETE requests in framework mode. A remote attacker can cause the victim's browser to send a crafted cross-site request to perform cross-site request forgery actions.
This issue does not affect applications using declarative mode or data mode.
Affected software
React Router
How to mitigate CVE-2026-53663
React Router - update to 7.15.1