← Vulnerability feed

Vulnerability record · CVE-2025-11953 · published 3 November 2025

CVE-2025-11953: React Native Community CLI Metro server OS command injection

RReact Native Community · React Native Community Cli

The Metro Development Server started by the React Native Community CLI binds to external interfaces by default and exposes an endpoint vulnerable to OS command injection. Unauthenticated network attackers can POST to that endpoint to run arbitrary executables, and on Windows also arbitrary shell commands with controlled arguments. Because the server is reachable over the network with no credentials, any developer machine or CI host running the CLI is exposed.

9.8 CVSS 3.1 Critical CISA KEV since 5 Feb 2026 EPSS 94% · top 0.2% CWE-78 · OS command injection
9.8CVSS 3.1 base score
94%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, confirmed KEV listing, very high EPSS, and exploit-tagged references make this an urgent remote code execution risk.

What it is

The Metro Development Server started by the React Native Community CLI binds to external interfaces by default and exposes an endpoint vulnerable to OS command injection. Unauthenticated network attackers can POST to that endpoint to run arbitrary executables, and on Windows also arbitrary shell commands with controlled arguments. Because the server is reachable over the network with no credentials, any developer machine or CI host running the CLI is exposed.

Impact

An attacker gains remote code execution on the host running the Metro Development Server, allowing arbitrary executables and, on Windows, arbitrary shell commands. This can lead to full compromise of the developer workstation or build environment and any secrets or source code it holds.

Attack surface

Reached over the network via a POST request to the exposed Metro endpoint; the CVSS vector shows AV:N/PR:N/UI:N, so no authentication and no user interaction are required. The default binding to external interfaces is what makes the service remotely reachable.

Exploitation

CVE-2025-11953 is listed in CISA KEV with a due date of 2026-02-26, and EPSS shows a 30-day probability of 0.9398 (99.84th percentile). Multiple references are tagged Exploit, including a VulnCheck blog titled met4shell_eitw, indicating exploitation in the wild.

What to do

  • Upgrade React Native Community CLI to a version containing the patch commit 15089907d1f1301b22c72d7f68846a2ef20df547.
  • If patching is not immediately possible, stop running the Metro Development Server or bind it to localhost only so it is not reachable from external interfaces.
  • Restrict network access to development servers with host firewalls or network segmentation; do not expose Metro ports to untrusted networks.
  • Follow CISA KEV required action and BOD 22-01 guidance, or discontinue use of the product if mitigations are unavailable.
  • Review developer and CI hosts that ran the CLI for signs of compromise before returning them to service.

Detection

  • Monitor network traffic and host logs for POST requests to Metro Development Server endpoints from unexpected or external source addresses.
  • Alert on child processes spawned by the Metro/Node process, especially command shells or unusual executables on developer and CI hosts.
  • Audit listening sockets for Metro ports bound to 0.0.0.0 or external interfaces on machines running the React Native Community CLI.
  • Hunt for command-line patterns consistent with injected arguments in process creation logs on Windows hosts running the CLI.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-11953 to the Known Exploited Vulnerabilities catalog on 5 February 2026 as "React Native Community CLI OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 26 February 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-11953 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed7.8CVE-2026-83549SonicWall SMA1000 AMC OS Command InjectionThe SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary op…KEVEPSS 11%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed7.8CVE-2026-53362Linux kernel IPv6 UDP paged allocation out-of-bounds write__ip6_append_data() in the Linux kernel mis-accounts fraggap on the paged-allocation path, leaving the linear skb area undersized while pagedlen is o…KEVEPSS 0.71%analysed7.8CVE-2022-0995Linux kernel watch_queue out-of-bounds writeThe Linux kernel's watch_queue event notification subsystem contains an out-of-bounds write (CWE-787) that can overwrite kernel state. A local user c…KEVEPSS 8.8%analysed8.9CVE-2026-73570Zimbra Collaboration SNMP notification OS command injectionZimbra Collaboration Suite before 10.1.20 contains an OS command injection flaw in SNMP notification processing when the optional zimbra-snmp package…KEVEPSS 12%analysed

Source: NIST National Vulnerability Database (record CVE-2025-11953), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.