CVE-2025-43865

React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values ??of the data object passed to the HTML. This issue has been patched in version 7.5.2.
CVSS

No CVSS.

Configurations

No configuration.

History

25 Apr 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-25 01:15

Updated : 2025-04-25 01:15


NVD link : CVE-2025-43865

Mitre link : CVE-2025-43865


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity