CVE-2025-11953

CRITICAL KEV

React-native-community React Native C... - OS Command Injection

Title source: rule

Description

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

Exploits (6)

github WORKING POC 4 stars
by SaidBenaissa · powershellremote
https://github.com/SaidBenaissa/cve-2025-11953-vulnerability-demo
nomisec WORKING POC 1 stars
by N3k0t-dev · remote
https://github.com/N3k0t-dev/PoC-CVE-collection
nomisec WORKING POC
by boroeurnprach · remote-auth
https://github.com/boroeurnprach/CVE-2025-11953-PoC
nomisec WORKING POC
by Mr-In4inci3le · remote
https://github.com/Mr-In4inci3le/CVE-2025-11953-POC-
nomisec WORKING POC
by GhoStZA-debug · poc
https://github.com/GhoStZA-debug/PoC-CVE-collection

Scores

CVSS v3 9.8
EPSS 0.1862
EPSS Percentile 95.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2026-02-05
VulnCheck KEV 2025-12-21
ENISA EUVD EUVD-2025-37505
CWE
CWE-78
Status published
Products (5)
react-native-community/cli 20.0.0-alpha.0 - 20.0.0npm
react-native-community/cli-server-api 20.0.0-alpha.0 - 20.0.0npm
react-native-community/react_native_community_cli 18.0.0
react-native-community/react_native_community_cli 20.0.0 alpha0 (3 CPE variants)
react-native-community/react_native_community_cli 19.0.0 - 19.1.2
Published Nov 03, 2025
KEV Added Feb 05, 2026
Tracked Since Feb 18, 2026