CVE-2026-14802

HIGH

react create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injection

Title source: cna
STIX 2.1

Description

A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-376396 | react create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injection
https://vuldb.com/vuln/376396
Signature, Permissions Required signature permissions-required
VDB-376396 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/376396/cti
Third Party Advisory third-party-advisory
CVE-2026-14802 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-14802
Third Party Advisory third-party-advisory
Submit #850857 | Node.js create-react-app 12.0.1 OS Command Injection
https://vuldb.com/submit/850857

Scores

CVSS v3 7.3
EPSS 0.0132
EPSS Percentile 68.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-77 CWE-78
Status published
Products (2)
react/create-react-app 5.0.0
react/create-react-app 5.0.1
Published Jul 06, 2026
Tracked Since Jul 06, 2026