Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) via the unstable RSC APIs. An attacker can execute unauthorized actions by tricking a user into submitting crafted requests.
Note: This is only exploitable if the unstable RSC APIs are enabled in the application.