Critical RCE Flaw in React Native CLI Exposes Developers to Attacks
First seen 6 Nov 2025, 17:37 UTC
•
•84% similarity
•62
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A critical remote-code execution (RCE) vulnerability has been identified in the @react-native-community/cli package, affecting millions of developers. The flaw allows unauthenticated attackers to execute arbitrary OS commands via the Metro development server, which binds to all network interfaces by default. The vulnerability has a CVSS score of 9.8 and is tracked as CVE-2025-11953.
ThreatCluster AI
How this analysis works