/Vulnerability Library

React Native Community CLI - Unauthenticated OS Command Injection

CVE-2025-11953
Verified

Description

The Metro development server started by the React Native Community CLI binds to external network interfaces by default and exposes an unauthenticated /open-url endpoint. Affected versions pass the attacker supplied url value straight to the open() helper without validating the scheme, allowing an unauthenticated attacker to launch arbitrary executables on the developer machine. On Windows the request is dispatched through cmd, which permits arbitrary shell commands with fully controlled arguments. The fix was released as a backport across several release lines, so the version number alone does not indicate whether an instance is affected, and this template probes the endpoint behaviour instead.

Severity

Critical

CVSS Score

9.8

Exploit Probability

94%

Affected Product

react_native_community_cli

Published Date

July 29, 2026

Template Author

aryu-ru

CVE-2025-11953.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-11953
CWE ID:
cwe-78

References

https://jfrog.com/blog/cve-2025-11953-critical-react-native-community-cli-vulnerability/https://www.vulncheck.com/blog/metro4shell_eitwhttps://github.com/advisories/GHSA-399j-vxmf-hjvrhttps://github.com/react-native-community/cli/commit/15089907d1f1301b22c72d7f68846a2ef20df547https://nvd.nist.gov/vuln/detail/CVE-2025-11953

Remediation Steps

Upgrade @react-native-community/cli-server-api to 17.0.1, 18.0.1, 19.1.2 or 20.0.0 and later, whichever is the fixed release for the line in use. Where upgrading is not immediately possible, bind the Metro development server to the loopback interface with --host 127.0.0.1 and block inbound access to the bundler port.