Skip to content
CVE-2025-11953: Remote Code Execution Vulnerability in React Native Metro Server

CVE-2025-11953: Remote Code Execution Vulnerability in React Native Metro Server

First seen 6 Feb 2026, 18:16 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

A critical unauthenticated remote code execution (RCE) vulnerability, tracked as CVE-2025-11953 and known as Metro4Shell, has been identified in the React Native Metro development server. This vulnerability allows attackers to execute operating system commands without authentication, affecting users of the React Native framework. The vulnerability was added to the CISA KEV list for active exploitation on February 5, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 184d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Metro4Shell and CVE-2025-11953 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed