Описание
React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in and useNavigate. This issue is a follow up to CVE-2025-68470 and has been fixed in version 7.18.0.
Ссылки
EPSS
Процентиль: 40%
0.00493
Низкий
Дефекты
CWE-601
Связанные уязвимости
CVSS3: 5.4
redhat
8 дней назад
A flaw was found in React Router, a routing library for React applications. A remote attacker could exploit this vulnerability by crafting a malicious link that uses backslashes within the <Link> or useNavigate components. This could lead to an Open Redirect, allowing the attacker to redirect users to arbitrary external websites, potentially for phishing or other malicious purposes.
github
12 дней назад
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
EPSS
Процентиль: 40%
0.00493
Низкий
Дефекты
CWE-601