Input validation error in React Router - CVE-2025-68470

 

Input validation error in React Router - CVE-2025-68470

Published: June 19, 2026


Vulnerability identifier: #VU134929
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-68470
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to redirect the application to an external URL.

The vulnerability exists due to improper input validation in navigation path handling when processing attacker-supplied paths passed to navigate(), Link, or redirect(). A remote user can supply a crafted path to redirect the application to an external URL.

This issue only occurs when untrusted content is passed into navigation paths in application code.


Affected software

React Router
IBM Fusion HCI
Data Cataloging

How to mitigate CVE-2025-68470

Install security update from vendor's website.

React Router - addressed in versions 6.30.2, 7.0.0, 7.9.6
IBM Fusion HCI - update to 2.13.0
Data Cataloging - update to 2.5.3

External References

Related Security Bulletins