Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9jcx-v3wj-wh4m

Опубликовано: 08 янв. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

React Router has unexpected external redirect via untrusted paths

An attacker-supplied path can be crafted so that when a React Router application navigates to it via navigate(), <Link>, or redirect(), the app performs a navigation/redirect to an external URL. This is only an issue if developers pass untrusted content into navigation paths in their application code.

Пакеты

Наименование

react-router

npm
Затронутые версииВерсия исправления

>= 6.0.0, < 6.30.2

6.30.2

Наименование

react-router

npm
Затронутые версииВерсия исправления

>= 7.0.0, < 7.9.6

7.9.6

EPSS

Процентиль: 8%
0.00029
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 6.5
nvd
28 дней назад

React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an attacker-supplied path can be crafted so that when a React Router application navigates to it via navigate(), <Link>, or redirect(), the app performs a navigation/redirect to an external URL. This is only an issue if you are passing untrusted content into navigation paths in your application code. This issue has been patched in versions 6.30.2 and 7.9.6.

EPSS

Процентиль: 8%
0.00029
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-601