Skip to content

Conversation

@oep-renovate
Copy link
Contributor

@oep-renovate oep-renovate bot commented Jan 10, 2026

This PR contains the following updates:

Package Change Age Confidence
react-router (source) 6.30.16.30.2 age confidence

React Router has unexpected external redirect via untrusted paths

CVE-2025-68470 / GHSA-9jcx-v3wj-wh4m

More information

Details

An attacker-supplied path can be crafted so that when a React Router application navigates to it via navigate(), <Link>, or redirect(), the app performs a navigation/redirect to an external URL. This is only an issue if developers pass untrusted content into navigation paths in their application code.

Severity

  • CVSS Score: 6.5 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

remix-run/react-router (react-router)

v6.30.2: v6.30.2

Compare Source

See the changelog for release notes: https://github.com/remix-run/react-router/blob/v6/CHANGELOG.md#v6302


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@oep-renovate oep-renovate bot requested a review from a team as a code owner January 10, 2026 02:39
@github-actions github-actions bot added the Geti Tune UI Issues related to Geti Tune UI label Jan 10, 2026
@github-actions
Copy link

github-actions bot commented Jan 10, 2026

Docker Image Sizes

CPU

Image Size
geti-tune-cpu:pr-5164 2.88G
geti-tune-cpu:sha-9bb98f6 2.88G

GPU

Image Size
geti-tune-gpu:pr-5164 10.66G
geti-tune-gpu:sha-9bb98f6 10.66G

XPU

Image Size
geti-tune-xpu:pr-5164 8.72G
geti-tune-xpu:sha-9bb98f6 8.72G

@oep-renovate oep-renovate bot force-pushed the renovate/npm-react-router-vulnerability branch 3 times, most recently from adf0cb4 to ab6ae30 Compare January 15, 2026 02:44
@oep-renovate oep-renovate bot changed the title chore(deps): update dependency react-router to v6.30.2 [security] chore(deps): update dependency react-router to v6.30.2 [security] (develop) Jan 15, 2026
Signed-off-by: oep-renovate[bot] <212772560+oep-renovate[bot]@users.noreply.github.com>
@oep-renovate oep-renovate bot changed the title chore(deps): update dependency react-router to v6.30.2 [security] (develop) chore(deps): update dependency react-router to v6.30.2 [security] (release/2.6) Jan 15, 2026
@oep-renovate oep-renovate bot force-pushed the renovate/npm-react-router-vulnerability branch from ab6ae30 to a04593a Compare January 15, 2026 02:45
@oep-renovate oep-renovate bot changed the base branch from develop to release/2.6 January 15, 2026 02:45
@oep-renovate oep-renovate bot changed the title chore(deps): update dependency react-router to v6.30.2 [security] (release/2.6) chore(deps): update dependency react-router to v6.30.2 [security] (release/2.6) - autoclosed Jan 15, 2026
@oep-renovate oep-renovate bot closed this Jan 15, 2026
@oep-renovate oep-renovate bot deleted the renovate/npm-react-router-vulnerability branch January 15, 2026 02:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Geti Tune UI Issues related to Geti Tune UI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant