Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
JFrog researchers identified a critical remote code execution vulnerability (CVE-2025-11953) in the React Native CLI, impacting developers using versions 4.8.0 to 20.0.0-alpha.2. Developers are advised to update to the patched version to mitigate the risk of remote attacks.
A critical remote-code execution (RCE) vulnerability has been identified in the @react-native-community/cli package, affecting millions of developers. The flaw allows unauthenticated attackers to execute arbitrary OS commands via the Metro development server, which binds to all network interfaces by...
Hackers are exploiting the critical vulnerability CVE-2025-11953 in the Metro server for React Native, affecting developers on Windows, Linux, and macOS. The vulnerability allows unauthenticated attackers to execute arbitrary OS commands on Windows and run arbitrary executables on Linux and macOS wi...
A critical unauthenticated remote code execution (RCE) vulnerability, tracked as CVE-2025-11953 and known as Metro4Shell, has been identified in the React Native Metro development server. This vulnerability allows attackers to execute operating system commands without authentication, affecting users...