We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-43865

React Router allows pre-render data spoofing on React-Router framework mode



Description

React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values ​​of the data object passed to the HTML. This issue has been patched in version 7.5.2.

Reserved 2025-04-17 | Published 2025-04-25 | Updated 2025-04-25 | Assigner GitHub_M


HIGH: 8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Problem types

CWE-345: Insufficient Verification of Data Authenticity

Product status

>= 7.0, < 7.5.2
affected

References

github.com/...router/security/advisories/GHSA-cpj6-fhp6-mr6j

github.com/...ommit/c84302972a152d851cf5dd859ff332b354b70111

github.com/...ages/react-router/lib/server-runtime/routes.ts

cve.org (CVE-2025-43865)

nvd.nist.gov (CVE-2025-43865)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-43865

Support options

Helpdesk Chat, Email, Knowledgebase