CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2025-11953

🔥 Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-11-03
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

Affected Platforms (CPE)

📦
React Native Community

React Native Community Cli

>= 19.0.0 and < 19.1.2= 18.0.0= 20.0.0

References & Advisories

相關資安分析文章

相關漏洞威脅