CVE-2025-11953: React Native Community CLI OS Command Injection Vulnerability
Added to the CISA Known Exploited Vulnerabilities catalog on 05 Feb 2026. Vendor: React Native Community. Product: CLI.
React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a vulnerable endpoint exposed by the server. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. (due 26 Feb 2026)