ThreatCluster

Critical RCE Flaw in React Native CLI Exposes Developers to Attacks

First seen 6 Nov 2025, 17:37 UTC Csoonline 84% similarity 62

Article Content

Browse articles
ThreatCluster

A critical remote-code execution (RCE) vulnerability has been identified in the @react-native-community/cli package, affecting millions of developers. The flaw allows unauthenticated attackers to execute arbitrary OS commands via the Metro development server, which binds to all network interfaces by default. The vulnerability has a CVSS score of 9.8 and is tracked as CVE-2025-11953.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story