CVE-2025-11953: React Native Community CLI OS Command Injection Vulnerability

Published Nov 3, 2025
·
Updated

React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a vulnerable endpoint exposed by the server. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments.

Other sources

The Metro Development Server, which is opened by the React Native CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

GitHub

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

NVD

Affected Software

13 affected componentsFixes available
React Native Community CLI
npm/@react-native-community/cli-server-api>=18.0.0<18.0.1
18.0.1
npm/@react-native-community/cli-server-api>=19.0.0-alpha.0<19.1.2
19.1.2
npm/@react-native-community/cli-server-api>=20.0.0-alpha.0<20.0.0
20.0.0
npm/@react-native-community/cli>=18.0.0<18.0.1
18.0.1
npm/@react-native-community/cli>=19.0.0-alpha.0<19.1.2
19.1.2
npm/@react-native-community/cli>=20.0.0-alpha.0<20.0.0
20.0.0
React Native Community CLI
React-native-community React Native Community Cli>=19.0.0<19.1.2
React-native-community React Native Community Cli=18.0.0
React-native-community React Native Community Cli=20.0.0-alpha0
React-native-community React Native Community Cli=20.0.0-alpha1
React-native-community React Native Community Cli=20.0.0-alpha2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@react-native-community/cli-server-api to a version that resolves this vulnerability.

    Fixed in 18.0.1
  2. Upgrade

    Upgrade npm/@react-native-community/cli-server-api to a version that resolves this vulnerability.

    Fixed in 19.1.2
  3. Upgrade

    Upgrade npm/@react-native-community/cli-server-api to a version that resolves this vulnerability.

    Fixed in 20.0.0
  4. Upgrade

    Upgrade npm/@react-native-community/cli to a version that resolves this vulnerability.

    Fixed in 18.0.1
  5. Upgrade

    Upgrade npm/@react-native-community/cli to a version that resolves this vulnerability.

    Fixed in 19.1.2
  6. Upgrade

    Upgrade npm/@react-native-community/cli to a version that resolves this vulnerability.

    Fixed in 20.0.0
  7. Remove

    Remove npm/@react-native-community/cli-server-api from your environment.

    Discontinue use/uninstall the product if mitigations are unavailable.

  8. Remove

    Remove npm/@react-native-community/cli from your environment.

    Discontinue use/uninstall the product if mitigations are unavailable.

  9. Compensating control

    Apply mitigations per vendor instructions and follow applicable BOD 22-01 guidance for cloud services. If immediate patching is not possible, restrict network access to the Metro Development Server (for example with firewall rules, ACLs, or network isolation) until a fixed version is deployed.

Event History

Nov 3, 2025
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:31 PM
Data Sourced
via GitHub·06:31 PM
DescriptionSeverityWeaknessAffected Software
Feb 3, 2026
News Published
via BleepingComputer·02:00 PM
News Published
via BleepingComputer·02:07 PM
News Published
via The Register·07:01 PM
News Published
via The Register·07:05 PM
Feb 5, 2026
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-11953?

CVE-2025-11953 is classified as a critical vulnerability due to its potential for OS command injection.

2

How can I fix CVE-2025-11953?

To mitigate CVE-2025-11953, ensure that the Metro Development Server is configured to bind only to localhost and not expose endpoints to external interfaces.

3

Who is affected by CVE-2025-11953?

CVE-2025-11953 affects users of the Meta React Native CLI who run the Metro Development Server.

4

What type of attack does CVE-2025-11953 enable?

CVE-2025-11953 enables unauthenticated network attackers to perform OS command injection via crafted POST requests.

5

Does CVE-2025-11953 require authentication to exploit?

CVE-2025-11953 can be exploited without authentication, making it more dangerous for exposed servers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203