CVE-2025-11953

CRITICAL(9.8)KEVWahrscheinlich ausgenutzt

React Native Community CLI OS Command Injection Vulnerability

Beschreibung

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

KEV-Informationen

Hersteller
React Native Community
Produkt
CLI
Hinzugefügt am
5. Februar 2026
Fälligkeitsdatum
26. Februar 2026
Erforderliche Maßnahme
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS-Score

Vektorstring
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnen
Angriffsvektor
NETWORK
Angriffskomplexität
LOW
Erforderliche Privilegien
NONE
Benutzerinteraktion
NONE
Scope
UNCHANGED
Vertraulichkeitsauswirkung
HIGH
Integritätsauswirkung
HIGH
Verfügbarkeitsauswirkung
HIGH
Ausnutzbarkeitsscore
3.9
Auswirkungsscore
5.9

CWEs

Betroffene Produkte

HerstellerProduktVersion
react-native-communityreact native community cli>= 19.0.0, < 19.1.2; 18.0.0; 20.0.0

Referenzen

CVSS-Score

9.8
CRITICAL(9.8)

EPSS-Score

EPSS-Score62.38%
EPSS-Perzentil99.1%

Daten

Veröffentlicht3. November 2025
Zuletzt geändert17. Juni 2026
StatusAnalyzed
CVSS-Versionv3.1

Hilfe beim Schwachstellenmanagement?

Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.