← Back to browse · API

CVE-2025-11953

Severity
CRITICAL
CVSS
9.8
EPSS
0.61921
Risk score
85.87
CISA KEV
Yes
PoC
No
Published
2026-02-05
Modified
2026-02-05
First seen
2026-08-07
Aliases
EUVD-2025-37505, GHSA-399J-VXMF-HJVR
Products
React Native Community:CLI
Sources
euvd EUVD-2025-37505
cisa.gov CVE-2025-11953

Description

React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a vulnerable endpoint exposed by the server. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments.

References