CVE 9.8 CRITICAL

Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests_CVE-2025-11953

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

AI Analysis

Command injection vulnerability in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests

Basic Information

ID CVE-2025-11953
Source JFROG
Published Nov 3, 2025 at 16:35
Modified Nov 3, 2025 at 20:49

Affected Product

Vendor React Native Community
Product React Native Community CLI
Version 4.8.0
Affected Versions 4.8.0

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor React Native Community
Product React Native Community CLI
Version 4.8.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.