Skip to content

react-router GHSA-qwww-vcr4-c8h2 (high): replace temporary gate exception with real fix #199

Description

@mforce

Context

Advisory GHSA-qwww-vcr4-c8h2 — React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response — published 2026-07-25, severity high, vulnerable range react-router 7.12.0–8.2.0. Our SPA resolves react-router@7.18.1 via react-router-dom@^7.1.1, so the F146 npm vuln gate (#146) now blocks every PR's "Web typecheck, test, and build" job.

Why an exception instead of a bump

  • The only patched release is 8.3.0 — a semver-major migration (npm audit fix is a no-op; only --force would take it).
  • The version-7 dist-tag still points at 7.18.1: no 7.x backport exists yet.
  • The vulnerable code path is RSC mode (server actions). The SPA uses classic BrowserRouter client-side routing only — no RSC, no server actions — so the advisory is not reachable in Cluckwork.

Per the .github/security-exceptions.json policy (breaking-major fix → file the tracking PR/issue and link it), a temporary exception was added, expiring 2026-08-24.

Done means

Either:

  • react-router publishes a 7.x backport → bump lockfile, remove the exception; or
  • migrate web/ to react-router 8.x → remove the exception

Remove the entry from .github/security-exceptions.json in the same PR. If neither lands before 2026-08-24, the gate re-blocks and the exception must be consciously re-evaluated, not blindly extended.

Epic: #15

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions