Skip to content
COOEY

EXPOSURES › CVE-2025-11953

CVE-2025-11953

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-02-05 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-11953 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 90/100 rceexploited-in-wildunpatched

React Native CLI exposed to OS command injection, allowing unauthenticated remote code execution.

An unpatched vulnerability in the React Native CLI allowed attackers to execute arbitrary commands on Windows systems through its Metro Development Server, posing a severe security risk to DIB organizations.

Shame score — Critical unpatched remote code execution vulnerability in a widely-used tool.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a vulnerable endpoint exposed by the server. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.