« Back to list

React-native-community

React-native-community React Native Community CLI: vulnerabilities and CVEs

React-native-community React Native Community CLI has 1 published vulnerabilities, 1 of them in the last 12 months. 1 are rated critical and 1 are listed by CISA as actively exploited.

CVEs1
Last 12 months1
Critical1
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-11953Critical (9.8)94%⚠ Active exploitationNov 3, 2025
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-11953Critical (9.8)94%⚠ Active exploitationNov 3, 2025
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.