APromptRiskDBThreat intelligence atlas
AI Vulnerability Context

CVE-2025-11953 - React Native Community CLI

React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a vulnerable endpoint exposed by the server. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments.

AI Vulnerability ContextCISA KEVReact Native Community

Record summary

A quick snapshot of what this page covers.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEV
CVE ID
CVE-2025-11953
Vendor/project
React Native Community
Product
CLI
Vulnerability name
React Native Community CLI OS Command Injection Vulnerability
Date added
2026-02-05
Due date
2026-02-26
Known ransomware campaign use
Unknown
CWE-78

Exploit context

What the vulnerability is about.

No description available. The source record only contains identifiers and metadata.

Source

Where this page information comes from.