216.73.217.22

Metro4Shell: Exploitation of React Native's Metro Server in the Wild

· Published 04/02/2026 11:13 · Modified 04/02/2026 21:20

Export JSON

Essential information

Published
04/02/2026 11:13
Modified
04/02/2026 21:20
Tags
2026-02-04 CVE-2025-11953 linux metro server powershell react native remote code execution vulnerability exploitation windows
Related entities
1 vulnerabilities (cve), 5 observables, 7 techniques (mitre)

Description

A vulnerability in 's , dubbed Metro4Shell, has been exploited in the wild since December 21, 2025. The flaw allows unauthenticated remote attackers to execute arbitrary OS commands on systems. Exploitation involves a multi-stage -based loader delivered through cmd.exe, which disables Microsoft Defender, establishes a connection to an attacker-controlled host, and executes a downloaded binary. The attacks originated from multiple IP addresses and targeted both and systems. Despite ongoing exploitation, the vulnerability has not received widespread public acknowledgment, highlighting the gap between actual threats and recognized risks in cybersecurity.

External references