HomeSecurityVulnerability in React Native CLI puts millions of developers at risk

Vulnerability in React Native CLI puts millions of developers at risk

Details have emerged about a now-patched critical security vulnerability in the popular React Native npm package “@react-native-community/cli,” which could potentially be exploited to execute malicious operating system (OS) commands under certain circumstances.

See also: Warning! Serious vulnerabilities in Microsoft Teams

React Native vulnerability

“The vulnerability allows remote unauthenticated attackers to easily trigger arbitrary OS command execution on the machine running the react-native-community/cli development server, putting developers at significant risk,” said JFrog Senior Security Researcher Or Pelesin a report shared with The Hacker News.

The flaw, tracked as CVE-2025-11953, carries a CVSS score of 9.8 out of a maximum of 10.0, indicating critical severity. It also affects versions of the “@react-native-community/cli-server-api” from 4.8.0 to 20.0.0-alpha.2 and was fixed in version 20.0.0 released early last month.

The command-line toolkit, maintained by Meta, allows developers to build mobile apps with React Native. It receives around 1.5 to 2 million downloads per week.

See also: Hackers scan the internet for RCE vulnerability exploitation in XWiki

Vulnerability in React Native CLI puts millions of developers at risk

According to the software supply chain security firm, the flaw arises from the fact that the Metro development server used by React Native to build JavaScript code and resources connects to external interfaces by default (instead of localhost) and exposes an “ /open-url ” endpoint that is vulnerable to OS command injection.

As a result, an unauthenticated network attacker could exploit the flaw to send a specially crafted POST request to the server and execute arbitrary commands. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments, while on Linux and macOS, it can be abused to execute arbitrary binaries with limited parameter control.

While the issue has now been addressed, developers using React Native with a non-Metro-based framework as their development server are not affected.

See also: Android: Critical 0-click vulnerability allows RCE attacks

Vulnerability in React Native CLI puts millions of developers at risk

“This zero-day vulnerability is particularly dangerous due to its ease of exploitation, lack of authentication requirements, and broad attack surface,” Peles said. “It also exposes critical risks hidden in third-party code.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS