PT-2026-1914 · Unknown · React Router

CVE-2025-68470

·

Published

2026-01-08

·

Updated

2026-08-03

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions React Router versions 6.0.0 through 6.30.1 React Router versions 7.0.0 through 7.9.5
Description An attacker-supplied path can be crafted to force a React Router application to perform a navigation or redirect to an external URL. This occurs when the application navigates using the navigate() function, the <Link> component, or the redirect() function. This issue is only applicable if untrusted content is passed into navigation paths within the application code.
Recommendations Update to version 6.30.2 or later. Update to version 7.9.6 or later.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-68470
GHSA-9JCX-V3WJ-WH4M

Affected Products

React Router