ThreatCluster

Critical RCE Flaw in React Native CLI Exposes Development Servers

First seen 2 Dec 2025, 18:33 UTC Csoonline 84% similarity 33

Article Content

Browse articles
ThreatCluster

A critical remote-code execution (RCE) vulnerability in the @react-native-community/cli allows attackers to execute arbitrary OS commands via the Metro development server. This flaw arises because the server binds to all network interfaces by default, potentially exposing machines to external threats when started with standard commands. Developers using React Native are particularly affected by this security issue.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story