AI description
CVE-2025-43865 is a vulnerability affecting React Router, a routing library for React applications. Specifically, versions on the 7.0 branch prior to 7.5.2 are susceptible. The vulnerability stems from the possibility of modifying pre-rendered data by adding a header to the request. By exploiting this vulnerability, an attacker can completely spoof the contents and modify all the values of the data object passed to the HTML. This is achieved by manipulating the `X-React-Router-Prerender-Data` header. The issue has been addressed and patched in version 7.5.2 of React Router.
- Description
- React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values of the data object passed to the HTML. This issue has been patched in version 7.5.2.
- Source
- security-advisories@github.com
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 8.2
- Impact score
- 4.2
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
- Severity
- HIGH
- security-advisories@github.com
- CWE-345
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
36
🚨 CVE-2025-43865 🔴 HIGH (8.2) 🏢 remix-run - react-router 🏗️ >= 7.0, < 7.5.2 🔗 https://t.co/tg8NZCq7Ne 🔗 https://t.co/7QnIjVRwSH 🔗 https://t.co/ozSBW1pSpH #CyberCron #VulnAlert #InfoSec https://t.co/ThxHqUIBdT
@cybercronai
25 Apr 2025
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-43865 React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request.… https://t.co/tjecHQD72R
@CVEnew
25 Apr 2025
233 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
another research effort with @inzo____ led to the discovery of two new vulnerabilities in React Router (14M+ downloads/week), resulting in: - CVE-2025-43865 (High-8.2) - CVE-2025-43864 (High-7.5) https://t.co/ooTe702fat
@zhero___
24 Apr 2025
21739 Impressions
46 Retweets
407 Likes
160 Bookmarks
19 Replies
3 Quotes