CVE-2025-11953
CRITICAL KEVReact-native-community React Native C... - OS Command Injection
Title source: ruleDescription
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.
Exploits (6)
github
WORKING POC
4 stars
by SaidBenaissa · powershellremote
https://github.com/SaidBenaissa/cve-2025-11953-vulnerability-demo
nomisec
WORKING POC
by boroeurnprach · remote-auth
https://github.com/boroeurnprach/CVE-2025-11953-PoC
References (6)
Scores
CVSS v3
9.8
EPSS
0.1862
EPSS Percentile
95.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2026-02-05
VulnCheck KEV
2025-12-21
ENISA EUVD
EUVD-2025-37505
CWE
CWE-78
Status
published
Products (5)
react-native-community/cli
20.0.0-alpha.0 - 20.0.0npm
react-native-community/cli-server-api
20.0.0-alpha.0 - 20.0.0npm
react-native-community/react_native_community_cli
18.0.0
react-native-community/react_native_community_cli
20.0.0 alpha0 (3 CPE variants)
react-native-community/react_native_community_cli
19.0.0 - 19.1.2
Published
Nov 03, 2025
KEV Added
Feb 05, 2026
Tracked Since
Feb 18, 2026