BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Critical OS Command Injection Flaw Found in React Native CLI

Critical Command Injection Vulnerability Discovered and Patched in @react-native-community/cli Affecting Metro Development Server

  • A critical security flaw in the @react-native-community/cli npm package has been identified and fixed.
  • The flaw allowed remote attackers to execute operating system commands without authentication.
  • This vulnerability, CVE-2025-11953, has a severity score of 9.8 out of 10.
  • Affected versions ranged from 4.8.0 to 20.0.0-alpha.2, patched in version 20.0.0.
  • The issue involved the Metro development server exposing an endpoint vulnerable to command injection.

A critical security weakness was discovered and patched in the popular @react-native-community/cli package, which supports developers building React Native mobile apps. The vulnerability could let unauthenticated attackers execute harmful operating system commands on machines running the development server. The details were reported on November 4, 2025.

- Advertisement -

According to JFrog Senior Security Researcher Or Peles, the flaw is tracked as CVE-2025-11953 and carries a critical CVSS score of 9.8 out of 10. It affected the command-line interface versions 4.8.0 through 20.0.0-alpha.2 and was fixed in release 20.0.0.

The exposed vulnerability stemmed from the Metro development server binding to external network interfaces by default rather than just localhost. This server exposes an “/open-url” endpoint that accepts POST requests. The user input sent to this endpoint is passed unsafely to a function from the open NPM package, allowing attackers to run arbitrary OS commands.

Peles explained, “The server’s ‘/open-url’ endpoint handles a POST request that includes a user-input value that is passed to the unsafe open() function provided by the open NPM package, which will cause OS command execution.” On Windows systems, this permits executing shell commands with full argument control. On Linux and macOS, attackers can run arbitrary binaries with some parameter restrictions.

The package is maintained by Meta and downloads range between 1.5 million and 2 million weekly. Developers using React Native with frameworks that do not rely on the Metro server are not affected. As Peles noted, “This zero day vulnerability is particularly dangerous due to its ease of exploitation, lack of authentication requirements and broad attack surface.” The issue highlights risks in third-party components and underscores the importance of automated security testing in software supply chains.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Climbs Above $64K Despite $100M Hack

Bitcoin climbed above $64,000 on Monday, August 3, despite a hack that stole over...

Amazon’s $3 Trillion Milestone: Cramer Urges Investors to Buy

Amazon hit a $3 trillion market cap for the first time after shares surged...

BlackRock Launches Solana Tokenized Fund for Stablecoin Reserves

BlackRock launched the BlackRock Daily Reinvestment Stablecoin Reserve Vehicle (BRSRV) alongside tokenized on-chain shares...

Robinhood Opens Venture Capital Fund to Everyday Investors

Robinhood Markets is listing Robinhood Ventures Fund II (RVII) on the NYSE, opening venture...

Amazon Gains $560B in Market Cap as SpaceX Plummets

Amazon’s market cap surpassed $3 trillion for the first time, while SpaceX has lost...

Must Read

7 Best Cryptocurrency Lending Platforms in 2025 (Ranked & Reviewed)

QUICK LINKSOur MethodologyHow to Choose the Best Crypto Lending Platform: Key Factors to ConsiderIn-Depth Reviews of the 7 Best Crypto Lending Platforms1. Nexo -...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading