216.73.216.233

CVE-2025-11953

· Published 03/11/2025 18:15 · Modified 07/02/2026 23:53 · Author: The MITRE Corporation

Labels: CVE-2025-11953 2025-11-03CVE-2025-11953CWE-78[email protected]

Essential information

Published
03/11/2025 18:15
Modified
07/02/2026 23:53
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
Yes
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:H/A:H

CVSS metrics

Description

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

References