CVE detail
CVE-2025-11953
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 26.4 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
13 source links · newest first
- 9th February – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 9th February, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Romania’s national oil pipeline operator, Conpet, has suffered a cyberattack that disrupted its IT systems and took its website offline. The company said operational technology, including pipeline control and telecommunications systems, remained […]
vendorresearch.checkpoint.comFeb 9, 2026, 12:50 PM - U.S. CISA adds SmarterTools SmarterMail and React Native Community CLI flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SmarterTools SmarterMail and React Native Community CLI flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SmarterTools SmarterMail and React Native Community CLI flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: Attackers are […]
newssecurityaffairs.comFeb 6, 2026, 9:22 AM The security defect allows unauthenticated attackers to execute arbitrary code remotely via malicious HTTP requests.
newswww.securityweek.comFeb 6, 2026, 7:50 AM- Hackers abused React Native CLI flaw to deploy Rust malware before public disclosureSecurity Affairs
Hackers exploit a critical React Native CLI flaw (CVE-2025-11953) to run remote commands and drop stealthy Rust malware, weeks before public disclosure. Attackers are actively exploiting a critical flaw in the React Native CLI Metro server, tracked as CVE-2025-11953. The React Native CLI’s Metro dev server binds to external interfaces by default and exposes a […]
newssecurityaffairs.comFeb 3, 2026, 3:41 PM Albeit mainly considered a theoretical risk, the flaw has been exploited to disable protections and deliver malware.
newswww.securityweek.comFeb 3, 2026, 2:00 PMA critical remote-code execution (RCE) flaw in the widely used @react-native-community/cli (and its server API) lets attackers run arbitrary OS commands via the Metro development server, the default JavaScript bundler for React Native. In essence, launching the development server through standard commands (eg, npm start or npx react-native start) could expose the machine to external […]
newswww.csoonline.comNov 6, 2025, 12:30 PMArbitrary command/code execution has been demonstrated through the exploitation of CVE-2025-11953 on Windows, macOS and Linux.
newswww.securityweek.comNov 4, 2025, 4:10 PM- https://www.vulncheck.com/blog/metro4shell_eitwwww.vulncheck.com
No excerpt available.
Exploitwww.vulncheck.comNov 3, 2025, 5:15 PM No excerpt available.
Mitigationwww.cisa.govNov 3, 2025, 5:15 PMNo excerpt available.
Exploitx.comNov 3, 2025, 5:15 PMNo excerpt available.
Exploitx.comNov 3, 2025, 5:15 PMNo excerpt available.
Exploitjfrog.comNov 3, 2025, 5:15 PM- https://github.com/react-native-community/cli/commit/15089907d1f1301b22c72d7f68846a2ef20df547github.com
No excerpt available.
Exploitgithub.comNov 3, 2025, 5:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-66138CVSS 7.2 · High
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciousl…
- CVE-2026-63732CVSS 9.4 · Critical
9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY n…
- CVE-2026-16763CVSS 1.9 · Low
A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Configuration…
- CVE-2026-47670CVSS 9.4 · Critical
DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute…
- CVE-2026-6516CVSS 10.0 · Critical
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
- CVE-2026-16735CVSS 1.9 · Low
A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file index.js of the component Change…