Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-11953

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.07
EPSS Ranking 91.2%
CVSS Severity
CVSS v3 Score 9.8
Proposed Action
React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a vulnerable endpoint exposed by the server. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments.
Ransomware Campaign
Unknown
Products affected by CVE-2025-11953


Contact Us

Shodan ® - All rights reserved