Security
Loading…

CVE-2025-11953

UNKNOWNKnown Exploited
Description

React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a vulnerable endpoint exposed by the server. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments.

Timeline
Published:February 5th, 2026 12:00 AM
Last modified:February 5th, 2026 12:00 AM
Added to KEV:February 5th, 2026
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

React Native Community

Products

CLI
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute