CVE-2025-11953: Remote Code Execution Vulnerability in React Native Metro Server

CVE-2025-11953: Remote Code Execution Vulnerability in React Native Metro Server

First seen 6 Feb 2026, 18:16 UTC SocradarIndusface 96% similarity 52.5

Article Content

Browse articles
ThreatCluster

A critical unauthenticated remote code execution (RCE) vulnerability, tracked as CVE-2025-11953 and known as Metro4Shell, has been identified in the React Native Metro development server. This vulnerability allows attackers to execute operating system commands without authentication, affecting users of the React Native framework. The vulnerability was added to the CISA KEV list for active exploitation on February 5, 2026.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story