Millions of developers could be open to attack after critical flaws exploited – here’s what we know


  • CVE-2025-11953 allows OS command injection via Metro server in React Native CLI
  • Affects version 4.8.0-20.0.0-alpha.2; patched in 20.0.0; exploitation requires no approval
  • No confirmed exploit yet; limit server exposure or update immediately

A very popular npm package had a critical severity vulnerability that allowed threat actors in certain scenarios to run malicious commands, experts have warned.

Cybersecurity researchers from JFrog say the package in question is called “@react-native-community/cli,” made to help developers build React Native mobile applications and get up to two million downloads per week.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top