Skip to content
ThreatCluster

Critical RCE Vulnerability in React Native CLI Exposes Developers

First seen 23 Nov 2025, 03:35 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

A critical remote code execution (RCE) vulnerability has been identified in the @react-native-community/cli package, affecting millions of developers. The flaw, tracked as CVE-2025-11953, allows unauthenticated attackers to execute arbitrary OS commands via the Metro development server, which binds to all network interfaces by default. Developers using versions 4.8.0 to 20.0.0-alpha.2 are advised to update to the patched version to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 183d ago How this analysis works

More articles in this cluster (1)