Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

React Native CLI Flaw Exposed

November 5, 2025
Reading Time: 3 mins read
in Alerts

Microsoft is upgrading its Edge web browser with a new scareware sensor to accelerate the detection and blocking of tech support scams,

A newly patched, critical security vulnerability has come to light within the widely used @react-native-community/cli npm package, posing a significant risk of remote operating system (OS) command execution. This flaw, which affects the command-line tools that enable developers to build React Native mobile applications, could be exploited under specific conditions to run arbitrary OS commands. The issue also impacts the associated @react-native-community/cli-server-api package in versions 4.8.0 through 20.0.0-alpha.2. Given the package’s popularity, with approximately 1.5 million to 2 million weekly downloads, the potential attack surface was substantial.

The vulnerability, assigned the identifier CVE-2025-11953, has been given a critical severity rating of 9.8 out of 10.0 on the CVSS scale. According to security researchers, the flaw allows remote unauthenticated attackers to easily trigger arbitrary OS command execution on the machine hosting the development server. This is possible because the Metro development server, which React Native utilizes to build JavaScript code and assets, defaults to binding to external interfaces instead of the more secure localhost.

The root of the problem lies in the exposed /open-url endpoint of the Metro development server. This endpoint is susceptible to OS command injection because it processes a POST request that contains a user-supplied value. This user input is then passed unsafely to the open() function provided by the open NPM package, ultimately leading to the execution of OS commands. Consequently, an attacker on the network could send a specifically crafted POST request to the server and execute commands arbitrarily on the developer’s machine.

The practical risk of exploitation is high. On Windows systems, attackers could execute arbitrary shell commands with fully controlled arguments. While on Linux and macOS, the flaw can be abused to execute arbitrary binaries, albeit with more limited parameter control. The vulnerability is considered particularly dangerous due to its ease of exploitation, the lack of authentication required, and the broad attack surface presented to threat actors.

While the issue has since been resolved with the release of version 20.0.0 early last month, the incident highlights a critical point: the dangers hidden within third-party code in the software supply chain. Developers using React Native with a framework that does not rely on Metro as the development server are not affected. For all others, immediate updating is the only way to mitigate this zero-day risk, underscoring the vital need for comprehensive and automated security scanning to catch easily exploitable flaws before they impact organizations.

Reference:

  • Critical React Native CLI Flaw Exposed Millions Of Developers To Remote Attacks
Tags: Cyber AlertsCyber Alerts 2025CyberattackCybersecurityNovember 2025
ADVERTISEMENT

Related Posts

Chrome Addon Injects Hidden Solana Fees

JackFix Spreads Stealers Via Fake Updates

November 26, 2025
Chrome Addon Injects Hidden Solana Fees

RomCom Uses Fake Updates To Spread Malware

November 26, 2025
Chrome Addon Injects Hidden Solana Fees

Chrome Addon Injects Hidden Solana Fees

November 26, 2025
CISA Highlights Ongoing Spyware Campaign

Formatters Leak Thousands Of Secrets

November 25, 2025
CISA Highlights Ongoing Spyware Campaign

Second Wave Hits Thousands Of Repos

November 25, 2025
CISA Highlights Ongoing Spyware Campaign

CISA Highlights Ongoing Spyware Campaign

November 25, 2025

Latest Alerts

JackFix Spreads Stealers Via Fake Updates

RomCom Uses Fake Updates To Spread Malware

Chrome Addon Injects Hidden Solana Fees

Formatters Leak Thousands Of Secrets

Second Wave Hits Thousands Of Repos

CISA Highlights Ongoing Spyware Campaign

Subscribe to our newsletter

    Latest Incidents

    Exchange Online Outage Blocks Mail

    CodeRED Cyberattack Disrupts Alerts

    Hacker Takes Over Houston Radio Airwaves

    Canon Subsidiary Hit By Oracle Hack

    Harvard Reports Significant Data Breach

    Dartmouth Confirms Major Data Breach

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial