Логотип exploitDog
bind:CVE-2025-68470
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-68470

Количество 2

Количество 2

nvd логотип

CVE-2025-68470

около 1 месяца назад

React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an attacker-supplied path can be crafted so that when a React Router application navigates to it via navigate(), <Link>, or redirect(), the app performs a navigation/redirect to an external URL. This is only an issue if you are passing untrusted content into navigation paths in your application code. This issue has been patched in versions 6.30.2 and 7.9.6.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9jcx-v3wj-wh4m

около 1 месяца назад

React Router has unexpected external redirect via untrusted paths

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-68470

React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an attacker-supplied path can be crafted so that when a React Router application navigates to it via navigate(), <Link>, or redirect(), the app performs a navigation/redirect to an external URL. This is only an issue if you are passing untrusted content into navigation paths in your application code. This issue has been patched in versions 6.30.2 and 7.9.6.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-9jcx-v3wj-wh4m

React Router has unexpected external redirect via untrusted paths

CVSS3: 6.5
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу