CVE-2025-43865
HIGHReact Router 7.0.0-pre.0-7.5.1 - Insufficient Verification of Data Authenticity via Request Header
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-43865. PoCs published by pouriam23.
AI-analyzed exploit summary The repository appears to be a template for React Router applications with no exploit code or demonstration of CVE-2025-43865. It lacks any offensive techniques or vulnerability-specific details.
Description
React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values of the data object passed to the HTML. This issue has been patched in version 7.5.2.
Exploits (1)
The repository appears to be a template for React Router applications with no exploit code or demonstration of CVE-2025-43865. It lacks any offensive techniques or vulnerability-specific details.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H