Input validation error in React Router - CVE-2025-68470
Published: June 19, 2026
Vulnerability details
The vulnerability allows a remote user to redirect the application to an external URL.
The vulnerability exists due to improper input validation in navigation path handling when processing attacker-supplied paths passed to navigate(), Link, or redirect(). A remote user can supply a crafted path to redirect the application to an external URL.
This issue only occurs when untrusted content is passed into navigation paths in application code.
Affected software
IBM Fusion HCI
Data Cataloging
How to mitigate CVE-2025-68470
IBM Fusion HCI - update to 2.13.0
Data Cataloging - update to 2.5.3