CVE-2025-43865
CVSS 3.1 Score 8.2 of 10 (high)
Details
Published Apr 25, 2025
Updated: Apr 29, 2025
CWE ID 345
Summary
CVE-2025-43865 is a vulnerability affecting versions of React Router on the 7.0 branch before 7.5.2. This router for React enables an attacker to modify pre-rendered data by adding a header to a request. By doing so, the attacker can completely spoof the contents of the data object passed to the HTML, enabling them to manipulate all its values. This issue poses a serious security risk, and affected users are advised to upgrade to React Router version 7.5.2 to mitigate the vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- ReactRouter