Millions of developers could be attacked after critical flaw exploited – here’s what we know


  • CVE-2025-11953 allows OS command injection via Metro Server in React Native CLI
  • Affects versions 4.8.0 to 20.0.0-alpha.2; fixed in 20.0.0; the exploit requires no authentication
  • No operations confirmed yet; restrict server exposure or update immediately

A popular npm package contained a critical severity vulnerability that allowed threat actors in certain scenarios to execute malicious commands, experts warned.

Cybersecurity researchers at JFrog say the package in question is called “@react-native-community/cli,” designed to help developers create React Native mobile apps and driving up to two million downloads per week.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top