Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wrjc-x8rr-h8h6

Опубликовано: 23 июл. 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.1

Описание

React Router: Open redirect via backslash in and useNavigate (CVE-2025-68470 bypass)

This is a follow up to CVE-2025-68470. React Router was alerted to certain scenarios in which the fix there was incomplete so there still existed some scenarios where attacker supplied paths passed to navigation mechanisms could result in unexpected external navigations.

Пакеты

Наименование

react-router

npm
Затронутые версииВерсия исправления

>= 6.0.0, < 7.18.0

7.18.0

EPSS

Процентиль: 40%
0.00493
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 5.4
redhat
8 дней назад

A flaw was found in React Router, a routing library for React applications. A remote attacker could exploit this vulnerability by crafting a malicious link that uses backslashes within the <Link> or useNavigate components. This could lead to an Open Redirect, allowing the attacker to redirect users to arbitrary external websites, potentially for phishing or other malicious purposes.

nvd
8 дней назад

React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in <Link> and useNavigate. This issue is a follow up to CVE-2025-68470 and has been fixed in version 7.18.0.

EPSS

Процентиль: 40%
0.00493
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-601