Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-75w3-gmqx-993q | Waku: Cross-Origin CSRF on RSC Server Action Dispatch |
Thu, 03 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Waku is the minimal React framework. Prior to version 1.0.0-beta.1, Waku's RSC request dispatcher invokes server actions without validating the request's Origin (or Sec-Fetch-Site) header. A cross-origin web attacker can therefore cause a victim browser to issue an authenticated POST to a registered server action endpoint using a CORS-safelisted content type (text/plain), which does not trigger a preflight. Any state-mutating server action that the application exposes via 'use server' can be invoked with the victim's cookies attached. This issue has been patched in version 1.0.0-beta.1. | |
| Title | Waku: Cross-Origin CSRF on RSC Server Action Dispatch | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-03T18:34:19.918Z
Reserved: 2026-05-30T02:43:33.107Z
Link: CVE-2026-49455
Updated: 2026-09-03T18:34:07.524Z
Status : Received
Published: 2026-09-03T19:17:28.100
Modified: 2026-09-03T19:17:28.100
Link: CVE-2026-49455
No data.
OpenCVE Enrichment
Updated: 2026-09-03T20:15:06Z
Github GHSA