Details have emerged about a now-patched critical security vulnerability in the popular React Native npm package “@react-native-community/cli,” which could potentially be exploited to execute malicious operating system (OS) commands under certain circumstances.
See also: Warning! Serious vulnerabilities in Microsoft Teams

“The vulnerability allows remote unauthenticated attackers to easily trigger arbitrary OS command execution on the machine running the react-native-community/cli development server, putting developers at significant risk,” said JFrog Senior Security Researcher Or Pelesin a report shared with The Hacker News.
The flaw, tracked as CVE-2025-11953, carries a CVSS score of 9.8 out of a maximum of 10.0, indicating critical severity. It also affects versions of the “@react-native-community/cli-server-api” from 4.8.0 to 20.0.0-alpha.2 and was fixed in version 20.0.0 released early last month.
The command-line toolkit, maintained by Meta, allows developers to build mobile apps with React Native. It receives around 1.5 to 2 million downloads per week.
See also: Hackers scan the internet for RCE vulnerability exploitation in XWiki

According to the software supply chain security firm, the flaw arises from the fact that the Metro development server used by React Native to build JavaScript code and resources connects to external interfaces by default (instead of localhost) and exposes an “ /open-url ” endpoint that is vulnerable to OS command injection.
As a result, an unauthenticated network attacker could exploit the flaw to send a specially crafted POST request to the server and execute arbitrary commands. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments, while on Linux and macOS, it can be abused to execute arbitrary binaries with limited parameter control.
While the issue has now been addressed, developers using React Native with a non-Metro-based framework as their development server are not affected.
See also: Android: Critical 0-click vulnerability allows RCE attacks

“This zero-day vulnerability is particularly dangerous due to its ease of exploitation, lack of authentication requirements, and broad attack surface,” Peles said. “It also exposes critical risks hidden in third-party code.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
