CVE-2025-43865

Publication date

2025-04-25 00:18:53

Family

GitHub_M

State

PUBLISHED

Description

React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, its possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values ​​of the data object passed to the HTML. This issue has been patched in version 7.5.2.