A critical vulnerability, tracked as CVE-2025-11953, was discovered in the @react-native-community/cli npm package, which is widely used for developing React Native mobile applications. The flaw, rated with a CVSS score of 9.8, allows unauthenticated remote attackers to execute arbitrary operating system commands on machines running the React Native CLI's development server. The vulnerability stems from the Metro development server binding to external interfaces by default and exposing an /open-url endpoint that is susceptible to OS command injection. Attackers can exploit this by sending specially crafted POST requests, leading to remote code execution. On Windows systems, attackers can execute arbitrary shell commands with full argument control, while on Linux and macOS, arbitrary binaries can be executed with limited parameter control.
The issue affects versions 4.8.0 through 20.0.0-alpha.2 of the @react-native-community/cli-server-api package and has been patched in version 20.0.0. The vulnerability posed a significant risk to millions of developers, as the package receives up to 2 million downloads per week. The flaw has since been addressed, but organizations using affected versions are urged to update immediately to mitigate the risk of exploitation. The vulnerability was reported by JFrog researchers and publicly disclosed in early November 2025.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Security coverage recommended immediate mitigation for unpatched environments by restricting the React Native development server to localhost instead of exposing it on all network interfaces. This guidance was issued alongside calls to update to secure versions.
Public reporting detailed that the Metro development server binds to 0.0.0.0 by default and that its /open-url endpoint passes attacker-controlled input to the open NPM package, enabling arbitrary OS command execution. Reports also noted Windows systems were especially at risk, though macOS and Linux could also be affected.
Meta released fixes for the React Native CLI vulnerability, with reports indicating the issue is fixed in version 20.0.0. Developers were advised to upgrade to patched versions to prevent exploitation.
CVE-2025-11953 was publicly listed as a high-severity vulnerability affecting React Native CLI, describing a command injection issue that allows remote attackers to achieve remote code execution by sending HTTP requests. Public disclosure established the issue as a tracked vulnerability.
JFrog researchers identified a critical command injection vulnerability in the @react-native-community/cli and its server API that could allow unauthenticated remote code execution through the Metro development server. The flaw was later tracked as CVE-2025-11953 and affects versions 4.8.0 through 20.0.0-alpha.2.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcesecurityonline.info
Open sourcescworld.com
Open sourcehackread.com
Open sourcethehackernews.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.