Vulnerability record · CVE-2025-11953 · published 3 November 2025
CVE-2025-11953: React Native Community CLI Metro server OS command injection
RReact Native Community · React Native Community Cli
The Metro Development Server started by the React Native Community CLI binds to external interfaces by default and exposes an endpoint vulnerable to OS command injection. Unauthenticated network attackers can POST to that endpoint to run arbitrary executables, and on Windows also arbitrary shell commands with controlled arguments. Because the server is reachable over the network with no credentials, any developer machine or CI host running the CLI is exposed.
Description
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, confirmed KEV listing, very high EPSS, and exploit-tagged references make this an urgent remote code execution risk.
What it is
The Metro Development Server started by the React Native Community CLI binds to external interfaces by default and exposes an endpoint vulnerable to OS command injection. Unauthenticated network attackers can POST to that endpoint to run arbitrary executables, and on Windows also arbitrary shell commands with controlled arguments. Because the server is reachable over the network with no credentials, any developer machine or CI host running the CLI is exposed.
Impact
An attacker gains remote code execution on the host running the Metro Development Server, allowing arbitrary executables and, on Windows, arbitrary shell commands. This can lead to full compromise of the developer workstation or build environment and any secrets or source code it holds.
Attack surface
Reached over the network via a POST request to the exposed Metro endpoint; the CVSS vector shows AV:N/PR:N/UI:N, so no authentication and no user interaction are required. The default binding to external interfaces is what makes the service remotely reachable.
Exploitation
CVE-2025-11953 is listed in CISA KEV with a due date of 2026-02-26, and EPSS shows a 30-day probability of 0.9398 (99.84th percentile). Multiple references are tagged Exploit, including a VulnCheck blog titled met4shell_eitw, indicating exploitation in the wild.
What to do
- Upgrade React Native Community CLI to a version containing the patch commit 15089907d1f1301b22c72d7f68846a2ef20df547.
- If patching is not immediately possible, stop running the Metro Development Server or bind it to localhost only so it is not reachable from external interfaces.
- Restrict network access to development servers with host firewalls or network segmentation; do not expose Metro ports to untrusted networks.
- Follow CISA KEV required action and BOD 22-01 guidance, or discontinue use of the product if mitigations are unavailable.
- Review developer and CI hosts that ran the CLI for signs of compromise before returning them to service.
Detection
- Monitor network traffic and host logs for POST requests to Metro Development Server endpoints from unexpected or external source addresses.
- Alert on child processes spawned by the Metro/Node process, especially command shells or unusual executables on developer and CI hosts.
- Audit listening sockets for Metro ports bound to 0.0.0.0 or external interfaces on machines running the React Native Community CLI.
- Hunt for command-line patterns consistent with injected arguments in process creation logs on Windows hosts running the CLI.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-11953 to the Known Exploited Vulnerabilities catalog on 5 February 2026 as "React Native Community CLI OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 26 February 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/react-native-community/cli/commit/15089907d1f1301b22c72d7f68846a2ef20df547 | Patch |
| https://jfrog.com/blog/cve-2025-11953-critical-react-native-community-cli-vulnerability | ExploitMitigationThird Party Advisory |
| https://x.com/SzymonRybczak/status/1986199665000566848 | Third Party Advisory |
| https://x.com/thymikee/status/1986770875954475375 | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-11953 | US Government Resource |
| https://www.vulncheck.com/blog/metro4shell_eitw | ExploitThird Party Advisory |
Track CVE-2025-11953 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-11953), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.