EXPOSURES › CVE-2025-11953
CVE-2025-11953
HIGH ⌖ ON CISA KEV · EXPLOITEDReact Native CLI exposed to OS command injection, allowing unauthenticated remote code execution.
An unpatched vulnerability in the React Native CLI allowed attackers to execute arbitrary commands on Windows systems through its Metro Development Server, posing a severe security risk to DIB organizations.
Shame score — Critical unpatched remote code execution vulnerability in a widely-used tool.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a vulnerable endpoint exposed by the server. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments.