CVE-2025-11953 is a vulnerability tracked across 11 threat clusters and 16 intelligence report mentions on ThreatCluster. First observed November 5, 2025; most recent activity February 9, 2026.
JFrog researchers identified a critical remote code execution vulnerability (CVE-2025-11953) in the React Native CLI, impacting developers using versions 4.8.0 to 20.0.0-alpha.2. Developers are advised to update to the…
A critical remote-code execution (RCE) vulnerability has been identified in the @react-native-community/cli package, affecting millions of developers. The flaw allows unauthenticated attackers to execute arbitrary OS…
Hackers are exploiting the critical vulnerability CVE-2025-11953 in the Metro server for React Native, affecting developers on Windows, Linux, and macOS. The vulnerability allows unauthenticated attackers to execute…
A critical unauthenticated remote code execution (RCE) vulnerability, tracked as CVE-2025-11953 and known as Metro4Shell, has been identified in the React Native Metro development server. This vulnerability allows…
A critical remote code execution (RCE) vulnerability has been identified in the @react-native-community/cli package, affecting millions of developers. The flaw, tracked as CVE-2025-11953, allows unauthenticated…
The Pennsylvania Attorney General's Office confirmed that a ransomware attack in August 2025, attributed to the INC ransomware group, resulted in the theft of personal information, including names, Social Security…
A critical remote code execution (RCE) vulnerability (CVE-2025-11953) has been identified in the React Native CLI, affecting developers using versions 4.8.0 to 20.0.0-alpha.2. This flaw allows unauthenticated attackers…
A critical remote-code execution (RCE) vulnerability in the @react-native-community/cli allows attackers to execute arbitrary OS commands via the Metro development server. This flaw arises because the server binds to…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-11953 to its Known Exploited Vulnerabilities catalog, identifying an OS command injection flaw in the React Native Community CLI that…
Three cybersecurity professionals have been indicted for allegedly conducting ransomware attacks using the BlackCat (ALPHV) strain against five U.S. companies between May and November 2023. The accused, Ryan Clifford…