CVE-2026-39371
EUVD-2026-1988807.04.2026, 20:16
RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver functions exported from "use server" files could be invoked via GET requests, bypassing their intended HTTP method. In cookie-authenticated applications, this allowed cross-site GET navigations to trigger state-changing functions, because browsers send SameSite=Lax cookies on top-level GET requests. This affected all server functions -- both serverAction() handlers and bare exported functions in "use server" files. This vulnerability is fixed in 1.0.6.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redwoodjs | redwoodsdk | 1.0.1 ≤ 𝑥 < 1.0.6 |
| redwoodjs | redwoodsdk | 1.0.0:beta50 |
| redwoodjs | redwoodsdk | 1.0.0:beta51 |
| redwoodjs | redwoodsdk | 1.0.0:beta52 |
| redwoodjs | redwoodsdk | 1.0.0:beta53 |
| redwoodjs | redwoodsdk | 1.0.0:beta53_test20260205213024 |
| redwoodjs | redwoodsdk | 1.0.0:beta54 |
| redwoodjs | redwoodsdk | 1.0.0:beta55 |
| redwoodjs | redwoodsdk | 1.0.0:beta56 |
| redwoodjs | redwoodsdk | 1.0.0:beta57 |
| redwoodjs | redwoodsdk | 1.0.0:beta58 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration