Skip to content

CVE-2025-11953

CVE

Threat entity extracted from intelligence sources

Frequency
14
occurrences
First Seen
November 5, 2025
Last Seen
February 9, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

JFrog researchers identified a critical remote code execution vulnerability (CVE-2025-11953) in the React Native CLI, impacting developers using versions 4.8.0 to 20.0.0-alpha.2. Developers are advised to update to the patched version to mitigate the risk of remote attacks.

A critical remote-code execution (RCE) vulnerability has been identified in the @react-native-community/cli package, affecting millions of developers. The flaw allows unauthenticated attackers to execute arbitrary OS commands via the Metro development server, which binds to all network interfaces by...

Hackers are exploiting the critical vulnerability CVE-2025-11953 in the Metro server for React Native, affecting developers on Windows, Linux, and macOS. The vulnerability allows unauthenticated attackers to execute arbitrary OS commands on Windows and run arbitrary executables on Linux and macOS wi...

A critical unauthenticated remote code execution (RCE) vulnerability, tracked as CVE-2025-11953 and known as Metro4Shell, has been identified in the React Native Metro development server. This vulnerability allows attackers to execute operating system commands without authentication, affecting users...

Public Exploits

Checking GitHub for proof-of-concept code…

Related Clusters (10)

1 / 2

Related Articles (14)

1 / 3