CVE-2025-43865

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Apr 25, 2025
Updated: Apr 29, 2025
CWE ID 345

Summary

CVE-2025-43865 is a vulnerability affecting versions of React Router on the 7.0 branch before 7.5.2. This router for React enables an attacker to modify pre-rendered data by adding a header to a request. By doing so, the attacker can completely spoof the contents of the data object passed to the HTML, enabling them to manipulate all its values. This issue poses a serious security risk, and affected users are advised to upgrade to React Router version 7.5.2 to mitigate the vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share