PatchSiren

redwoodjs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH redwoodjs CVE published 2026-04-07

CVE-2026-39371

The RedwoodSDK, a server-first React framework, has a high-severity vulnerability tracked as CVE-2026-39371. This vulnerability affects versions from 1.0.0-beta.50 to 1.0.5, where server functions exported from 'use server' files could be invoked via GET requests, bypassing their intended HTTP method. In cookie-authenticated applications, this allowed cross-site GET navigations to trigger state-changing f [truncated]