React Native CLI is a technology platform tracked across 3 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity November 5, 2025.
React Native CLI is the command-line interface used to create, build, and manage React Native mobile apps. Recent disclosures describe a critical remote code execution vulnerability and a broad flaw in the CLI that could let attackers compromise development environments, given the tool's widespread adoption among millions of developers.
JFrog researchers identified a critical remote code execution vulnerability (CVE-2025-11953) in the React Native CLI, impacting developers using versions 4.8.0 to 20.0.0-alpha.2. Developers are advised to update to the…
A critical remote code execution (RCE) vulnerability has been identified in the @react-native-community/cli package, affecting millions of developers. The flaw, tracked as CVE-2025-11953, allows unauthenticated…
A critical remote code execution (RCE) vulnerability (CVE-2025-11953) has been identified in the React Native CLI, affecting developers using versions 4.8.0 to 20.0.0-alpha.2. This flaw allows unauthenticated attackers…