-
Notifications
You must be signed in to change notification settings - Fork 922
Description
CVE-2025-68470 - Medium Severity Vulnerability
Vulnerable Library - react-router-6.3.0.tgz
Declarative routing for React
Library home page: https://registry.npmjs.org/react-router/-/react-router-6.3.0.tgz
Path to dependency file: /vendor/cache/manageiq-ui-classic-744debc9ba0a/package.json
Path to vulnerable library: /vendor/cache/manageiq-ui-classic-744debc9ba0a/package.json
Dependency Hierarchy:
- ❌ react-router-6.3.0.tgz (Vulnerable Library)
Found in HEAD commit: 99489caead4b82daad011bd2d1b5f720b8428654
Found in base branch: master
Vulnerability Details
React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an attacker-supplied path can be crafted so that when a React Router application navigates to it via navigate(), , or redirect(), the app performs a navigation/redirect to an external URL. This is only an issue if you are passing untrusted content into navigation paths in your application code. This issue has been patched in versions 6.30.2 and 7.9.6.
Publish Date: 2026-01-10
URL: CVE-2025-68470
CVSS 3 Score Details (6.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: GHSA-9jcx-v3wj-wh4m
Release Date: 2026-01-08
Fix Resolution: 6.30.2
Step up your Open Source Security Game with Mend here