CVE-2025-68470

React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an attacker-supplied path can be crafted so that when a React Router application navigates to it via navigate(), <Link>, or redirect(), the app performs a navigation/redirect to an external URL. This is only an issue if you are passing untrusted content into navigation paths in your application code. This issue has been patched in versions 6.30.2 and 7.9.6.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*
cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*

History

17 Jun 2026, 09:59

Type Values Removed Values Added
Summary
  • (es) React Router es un router para React. En las versiones 6.0.0 a 6.30.1 y 7.0.0 a 7.9.5, una ruta proporcionada por un atacante puede ser diseñada de modo que cuando una aplicación de React Router navega a ella a través de navigate(), , o redirect(), la aplicación realiza una navegación/redirección a una URL externa. Esto es solo un problema si está pasando contenido no confiable a rutas de navegación en el código de su aplicación. Este problema ha sido parcheado en las versiones 6.30.2 y 7.9.6.

30 Jan 2026, 18:20

Type Values Removed Values Added
CPE cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*
First Time Shopify
Shopify react-router
References () https://github.com/remix-run/react-router/security/advisories/GHSA-9jcx-v3wj-wh4m - () https://github.com/remix-run/react-router/security/advisories/GHSA-9jcx-v3wj-wh4m - Third Party Advisory

10 Jan 2026, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-10 03:15

Updated : 2026-06-17 09:59


NVD link : CVE-2025-68470

Mitre link : CVE-2025-68470

CVE.ORG link : CVE-2025-68470


JSON object : View

Products Affected

shopify

  • react-router
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')