Skip to content
Hackers Exploit React Native Metro Vulnerability to Target Developers

Hackers Exploit React Native Metro Vulnerability to Target Developers

First seen 3 Feb 2026, 19:24 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Hackers are exploiting the critical vulnerability CVE-2025-11953 in the Metro server for React Native, affecting developers on Windows, Linux, and macOS. The vulnerability allows unauthenticated attackers to execute arbitrary OS commands on Windows and run arbitrary executables on Linux and macOS with limited control. This poses a significant risk to development environments using React Native.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 210d ago How this analysis works

More articles in this cluster (14)

Following this threat?

Track Metro4Shell, JFrog and CVE-2025-11953 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed