CVE-2025-11953Active Exploitation(react-native-community / react_native_community_cli)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 27 mentions and remains active

Immediate actions

  • Patch react-native-community react_native_community_cli systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-26. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-78

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • react_native_community_cli

Threat summary

  • Active exploitation appears in 76 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 93 mentions across 16 observed days

What's happening

  • Active exploitation reported across 76 signals
  • Exploit tool or code specified in 10 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 35 signals
  • Technical details provided in 63 signals
  • Disclosure: 12 classified signals
  • Peaked 13d ago at 27 mentions (2026-02-04); latest day: 1
  • 93 total mentions across 16 days

Affected systems

Products
react_native_community_cli

2 versions affected across 1 product

Deep dive

Activity timeline93 mentions / 16d
07142027Mentions · 2026-02-02: 1Mentions · 2026-02-03: 26Mentions · 2026-02-04: 27Mentions · 2026-02-05: 11Mentions · 2026-02-06: 9Mentions · 2026-02-07: 3Mentions · 2026-02-08: 2Mentions · 2026-02-09: 2Mentions · 2026-02-10: 3Mentions · 2026-02-13: 1Mentions · 2026-02-15: 1Mentions · 2026-02-18: 2Mentions · 2026-03-24: 1Mentions · 2026-05-21: 2Mentions · 2026-05-25: 1Mentions · 2026-08-07: 1PoC Mentioned / Linked · 2026-02-03: 1PoC Mentioned / Linked · 2026-02-04: 2PoC Mentioned / Linked · 2026-02-05: 1Exploit Tool / Code · 2026-02-03: 5Exploit Tool / Code · 2026-02-04: 3Exploit Tool / Code · 2026-02-05: 1Exploit Tool / Code · 2026-02-09: 1Active Exploitation · 2026-02-03: 24Active Exploitation · 2026-02-04: 24Active Exploitation · 2026-02-05: 7Active Exploitation · 2026-02-06: 8Active Exploitation · 2026-02-07: 3Active Exploitation · 2026-02-08: 2Active Exploitation · 2026-02-09: 2Active Exploitation · 2026-02-10: 3Active Exploitation · 2026-02-13: 1Active Exploitation · 2026-02-15: 1Active Exploitation · 2026-05-25: 1Patch / Workaround · 2026-02-02: 1Patch / Workaround · 2026-02-03: 10Patch / Workaround · 2026-02-04: 14Patch / Workaround · 2026-02-05: 3Patch / Workaround · 2026-02-06: 5Patch / Workaround · 2026-02-07: 1Patch / Workaround · 2026-02-10: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-03: 17Technical Details · 2026-02-04: 14Technical Details · 2026-02-05: 8Technical Details · 2026-02-06: 7Technical Details · 2026-02-07: 2Technical Details · 2026-02-08: 2Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 3Technical Details · 2026-02-13: 1Technical Details · 2026-02-15: 1Technical Details · 2026-02-18: 2Technical Details · 2026-03-24: 1Technical Details · 2026-05-21: 2Technical Details · 2026-08-07: 102-0202-0302-0402-0502-0602-0702-0802-0902-1002-1302-1502-1803-2405-2105-2508-07
Signal classification4 categories
Active Exploitation
7580.6%
Disclosure
1212.9%
Patch
44.3%
General
22.2%
Referenced assets124 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-021
Patch1
2026-02-0326
Active Exploitation24General1Patch1
2026-02-0427
Active Exploitation23Disclosure3General1
2026-02-0511
Active Exploitation7Disclosure3Patch1
2026-02-069
Active Exploitation8Patch1
2026-02-073
Active Exploitation3
2026-02-082
Active Exploitation2
2026-02-092
Active Exploitation2
2026-02-103
Active Exploitation3
2026-02-131
Active Exploitation1
2026-02-151
Active Exploitation1
2026-02-182
Disclosure2
2026-03-241
Disclosure1
2026-05-212
Disclosure2
2026-05-251
Active Exploitation1
2026-08-071
Disclosure1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Researchers detect active exploitation of a critical React Native CLI flaw. CVE-2025-11953 allows unauthenticated OS command execution on exposed Metro dev servers, with attacks deploying PowerShell and a Rust payload. 🔗 Read → https://thehackernews.com/2026/02/hackers-exploit-metro4shell-rce-flaw-in.html

    Post summary

    Researchers confirm that CVE-2025-11953 is being actively exploited for OS command execution on exposed Metro dev servers, with attackers leveraging PowerShell and a Rust payload.

    53721132412.1K
    1.0M followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added React Native community CLI vulnerability CVE-2025-11953 & SmarterTools SmarterMail vulnerability CVE-2026-24423 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity https://t.co/rBMaOkPRwE

    Post summary

    DHS added CVE‑2025‑11953 and CVE‑2026‑24423 to its Known Exploited Vulnerabilities Catalog, indicating these vulnerabilities are being actively exploited, and urges applying mitigations.

    421058118.6K
    291.8K followersView on X
  • Teegra 🧝‍♀️𝕏@Teeegra
    Active Exploitation

    مهاجمان سایبری در حال سوءاستفاده از آسیب‌پذیری بحرانی CVE-2025-11953 (با نام مستعار Metro4Shell) در بسته npm محبوب "@react-native-community/cli" هستند. این نقص امنیتی که امتیاز CVSS آن ۹.۸ است، به مهاجمان غیرمجاز از راه دور اجازه می‌دهد دستورات دلخواه سیستم عامل را بر روی سرور اجرا کنند. شرکت امنیت سایبری VulnCheck اعلام کرد که اولین بار در ۲۱ دسامبر ۲۰۲۵ شاهد بهره‌برداری از این آسیب‌پذیری بوده است، در حالی که جزئیات آن توسط JFrog در نوامبر ۲۰۲۵ مستندسازی شده بود. در حملات شناسایی‌شده، مهاجمان از اسکریپت پاورشل رمزگذاری‌شده Base64 استفاده کرده‌اند که پس از اجرا، استثناهایی برای آنتی‌ویروس Microsoft Defender ایجاد می‌کند و از طریق اتصال TCP به سرور مهاجم، فایل مخربی مبتنی بر Rust را دانلود و اجرا می‌کند. آژانس امنیت سایبری و زیرساخت‌های آمریکا (CISA) در ۵ فوریه ۲۰۲۶ این آسیب‌پذیری را به فهرست آسیب‌پذیری‌های شناخته‌شده مورد سوءاستفاده (KEV) اضافه کرد و از سازمان‌های دولتی فدرال خواست تا ۲۶ فوریه ۲۰۲۶ اقدامات اصلاحی را اعمال کنند. VulnCheck تأکید کرد که این حملات عملیاتی و هدفمند بوده و نه آزمایشی، و هشدار داد که زیرساخت‌های توسعه به محض دسترس‌پذیر شدن، به زیرساخت تولید تبدیل می‌شوند.

    Post summary

    CVE‑2025‑11953 is being actively exploited via a PowerShell‑based RCE in the npm package; attacks have been documented and added to CISA’s KEV list, but no patch or workaround has been mentioned.

    01033152.3K
    18.8K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-11953 - critical 🚨 React Native Community CLI - Unauthenticated OS Command Injection > The Metro development server started by the React Native Community CLI binds to exter... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-11953 @pdnuclei #NucleiTemplates ...

    Post summary

    The post announces CVE-2025-11953, describing it as a critical unauthenticated OS command injection in React Native Community CLI, and provides a link to additional information, but offers no exploit code or patch details.

    0602261.5K
    1.3K followersView on X
  • Nur@winxf1perisi
    Active Exploitation

    React Native Metro dev server’daki Metro4Shell (CVE-2025-11953) açığıyla RCE mümkün. Bu zafiyetin Aralık 2025’ten beri exploit edildiği raporlanmıştı ve Şubat 2026 itibarıyla saldırıların hâlâ aktif olduğu görülüyor

    Post summary

    CVE-2025-11953 (Metro4Shell) in the React Native Metro dev server has been actively exploited since December 2025, with attacks continuing as of February 2026.

    100330701
    870 followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CISA has added two vulnerabilities to the KEV Catalog https://darkwebinformer.com/cisa-kev-catalog/ CVE-2026-24423: SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability: SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS command and could lead to command execution. CVE-2025-11953: React Native Community CLI OS Command Injection Vulnerability: React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a vulnerable endpoint exposed by the server. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments.

    Post summary

    CISA has announced two vulnerabilities—CVE‑2026‑24423 in SmarterMail and CVE‑2025‑11953 in React Native CLI—as part of its KEV catalog, providing technical details but no patch or exploit information.

    0501553.7K
    164.9K followersView on X
  • Caitlin Condon@catc0n
    Active Exploitation

    Earlier today, @Junior_Baines wrote about in-the-wild exploitation of React Metro Server CVE-2025-11953, which @VulnCheckAI's Canary Intelligence network has been observing since December. Analysis: https://www.vulncheck.com/blog/metro4shell_eitw

    Post summary

    CVE-2025-11953 is being actively exploited in the wild, as reported by @Junior_Baines and observed by VulnCheckAI's Canary Intelligence network since December.

    0501442.8K
    3.5K followersView on X
  • SOCRadar®@socradar
    Active Exploitation

    Critical Alert: CVE-2025-11953 "Metro4Shell" enables unauthenticated RCE in React Native Metro Server. Attackers are actively exploiting this CVSS 9.8 flaw to compromise developer environments and CI pipelines exposed to the network. Read the full report: https://socradar.io/blog/cve-2025-11953-metro4shell-react-native-metro-rce/ #CyberSecurity #Metro4Shell #RCE

    Post summary

    CVE‑2025‑11953, dubbed Metro4Shell, is an unauthenticated RCE in the React Native Metro Server with a CVSS score of 9.8, and attackers are currently exploiting it in developer environments and CI pipelines.

    11082519
    5.6K followersView on X
  • 中島佑允(YusukeNakajima)@nakajimeeee
    Active Exploitation

    【サプライチェーン攻撃】React Native CLIの脆弱性「Metro4Shell」が実際の攻撃で悪用、開発環境が標的に サイバーセキュリティ企業VulnCheckは、React Native開発で広く使用されるnpmパッケージ「@react-native-community/cli」のMetro開発サーバーに存在する重大な脆弱性(CVE-2025-11953、CVSS 9.8)が実際に悪用されていることを確認した。2025年12月21日に最初の攻撃を観測したが、1か月以上経過しても広く認知されていないという。 攻撃者はこの脆弱性を利用してBase64エンコードされたPowerShellスクリプトを配信する。スクリプトはWindows Defenderの除外設定を追加し、外部サーバーからRust製のバイナリをダウンロード・実行する。このバイナリには静的解析を妨害する機能が含まれている。 VulnCheckは、攻撃が数週間にわたり一貫したペイロードを使用していることから、単なる脆弱性検証ではなく実運用段階にあると分析。「開発インフラは外部からアクセス可能になった瞬間に本番インフラとなる」と警告しており、開発環境のセキュリティ対策の重要性を改めて示す事例である。 https://thehackernews.com/2026/02/hackers-exploit-metro4shell-rce-flaw-in.html

    Post summary

    VulnCheck reports that CVE‑2025‑11953 (Metro4Shell) is actively exploited in the wild, with attackers using a Base64‑encoded PowerShell payload to download a Rust binary and bypass Windows Defender. The vulnerability, rated CVSS 9.8, remains largely unpublicized.

    03071994
    2.4K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/5追加) 🛡️No.1507 CVE-2025-11953 React Native Community CLI OS Command Injection Vulnerability ============= CVSSスコア: 9.8 (Base) / JFrog CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:OSコマンドインジェクション (CWE-78 / JFrog) 深刻度:深刻🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートからMetro 開発サーバーに 細工されたPOST リクエストを送信することで、任意のファイルを実行される恐れがあります。Windows では、攻撃者は完全に制御された引数を使用して任意のシェルコマンドを実行される恐れがあります。 この脆弱性はランサムウェア事案での悪用が確認されています。 https://github.com/react-native-community/cli/commit/15089907d1f1301b22c72d7f68846a2ef20df547 https://github.com/react-native-community/cli/pull/2735 🛡️No.1508 CVE-2026-24423 SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability ============= CVSSスコア: 9.3 (Base) / VulnCheck CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 種別:重要な機能に対する認証の欠如 (CWE-306 / VulnCheck) 深刻度:深刻🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、SmarterMail インスタンスを悪意のある HTTP サーバーに誘導し、OS コマンドを実行される恐れがあります。 https://www.smartertools.com/smartermail/release-notes/current CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/02/05/cisa-adds-two-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA has added two CVEs to its Known Exploited Vulnerabilities catalog, confirming real‑world exploitation—especially in ransomware incidents—while no PoC or exploit code and no patch information are explicitly shared.

    010904.2K
    42.5K followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    React Native CLIの脆弱性"Metro4Shell" (CVE-2025-11953)が2025/12/21から悪用されている。VulnCheck社報告。 https://thehackernews.com/2026/02/hackers-exploit-metro4shell-rce-flaw-in.html

    Post summary

    CVE-2025-11953, dubbed "Metro4Shell", is being actively exploited in the wild as reported by VulnCheck.

    00041858
    7.2K followersView on X
  • Sam Stepanyan@securestep9
    Active Exploitation

    #ReactNative: Critical vulnerability in Metro server for #React Native CVE-2025-11953 allows unauthenticated attackers to execute arbitrary OS commands via a POST request is actively exploited - patch now! #Metro4Shell #SoftwareSupplyChainSecurity 👇 https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-react-native-metro-bug-to-breach-dev-systems/

    Post summary

    CVE-2025-11953 is a critical remote code execution flaw in React Native's Metro server that is currently being exploited; a patch is immediately available.

    00013185
    7.3K followersView on X
  • Averlon@Averlon_ai
    Disclosure

    You’ve got a new 9.8 vulnerability. CVE-2025-11953 (Command injection in React Native CLI) What do you do? Every issue follows the same path: Understand → Determine relevance → Fix Most teams can do this. They just can’t do it at scale. Understanding the vulnerability alone can take tens of minutes per issue. But that’s just one layer. You still need to understand: • Your environment • Conditions for exploit • Existing safeguards Now multiply that across thousands of issues. We built Vulnerability Intelligence (VI), free for analysts, to handle the vulnerability context. Example: https://www.averlon.ai/blog/vulnerability-intelligence-brief-cve-2025-11953-react-native-metro-command-injection And once that’s clear, the next challenge is determining relevance in your environment and fixing it safely, at scale. That’s where Remediation Operations comes in.

    Post summary

    The post announces a high‑severity command‑injection vulnerability (CVE‑2025‑11953) in React Native CLI, outlines steps for assessing relevance and remediation, and directs readers to a blog for further vulnerability context.

    00030184
    36 followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    CISA KEV 警告 26/02/05:React Native Community CLI の脆弱性 CVE-2025-11953 を登録 https://iototsecnews.jp/2026/02/06/cisa-warns-of-react-native-community-command-injection-vulnerability-exploited-in-attacks/ この問題の原因は、React Nativeプロジェクトの管理に使われるCommunity CLIにおいて、外部からの入力を適切に検証せずにシステムコマンドとして実行してしまう設計上の不備にあります。具体的には、開発用サーバーである Metro bundler が稼働している際に、認証なしで送信された特定の POST リクエストに含まれる引数を、そのままシェルに渡してしまうという問題があります、それにより、リモートから OS コマンドを実行される “OSコマンド・インジェクション” が成立してしまいます。この脆弱性 CVE-2025-11953 が、CISAの KEV に登録されたことで、米政府組織内での悪用が明らかになりました。ご利用のチームは、ご注意ください。 #CISA #CVE202511953 #Exploit #Government #KEV #NativeCommunityCLI #React #Vulnerability

    Post summary

    CISA KEV warns of an OS command injection vulnerability (CVE-2025-11953) in React Native Community CLI, with confirmed active exploitation in U.S. government organizations; no patch or PoC is referenced.

    02010183
    483 followersView on X
  • twelvesec@twelvesec
    Active Exploitation

    #Hackers managed to exploit a critical React Native CLI flaw (CVE-2025-11953) to run remote commands and drop stealthy #Rust #malware. #CyberSecurity #InfoSec https://ift.tt/xJgCD5k https://t.co/P87EPC00WU

    Post summary

    The tweet reports that hackers exploited CVE‑2025‑11953 to execute remote commands via a critical React Native CLI flaw and dropped stealthy Rust malware, indicating active exploitation.

    01020181
    1.5K followersView on X
  • DataHogo@DataHogo
    Disclosure

    Your React Native dev server is running on port 8081. Anyone on your network can send it a command. CVE-2025-11953 — CVSS 9.8. The Metro bundler accepted unauthenticated requests and executed whatever was in them. SSH keys. AWS credentials. Environment variables. All accessible from the machine running npm start. Coffee shop WiFi. Hotel network. Conference hall. Check which version of @react-native-community/cli you're running. #reactnative #javascript #cybersecurity #mobiledev

    Post summary

    The post discloses CVE-2025-11953, a critical RCE in the React Native dev server that allows unauthenticated execution of commands over the network, with no current patch or exploit code referenced.

    01010754
    3 followersView on X
  • codyAtwork@AtworkCody
    Active Exploitation

    Hey React Native friends, big news! A critical vulnerability (CVE-2025-11953) in the Metro dev server is under active attack right now. It allows remote code execution, so definitely update your projects and stay safe out there!

    Post summary

    CVE-2025-11953 is being actively exploited to achieve remote code execution; developers are urged to update their React Native projects to mitigate the threat.

    1000155
    26 followersView on X
  • Zero Day Wire@zerodaywire
    Active Exploitation

    🚨Hackers Exploit Critical React Native Metro Flaw to Compromise Developer Systems (CVE-2025-11953) 🔗 https://zerodaywire.com/article.html?slug=hackers-exploit-critical-react-native-metro-flaw-to-compromise-developer-systems-cve-2025-11953 #cybersecurity #infosec #threatintel https://t.co/RsHLxgXd3I

    Post summary

    The tweet announces that hackers are actively exploiting CVE‑2025‑11953, a critical flaw in React Native Metro, to compromise developer systems, but provides no PoC, exploit details, or mitigation information.

    2000086
    134 followersView on X
  • Mert SARICA@MertSARICA
    Disclosure

    CVE-2025-11953 (Metro4Shell) in React Native Metro Server Enables RCE https://socradar.io/blog/cve-2025-11953-metro4shell-react-native-metro-rce/

    Post summary

    The text announces CVE-2025-11953, named Metro4Shell, as a new RCE vulnerability in the React Native Metro server, with a link that likely contains a proof‑of‑concept.

    01010281
    7.4K followersView on X
  • transilienceai@transilienceai
    General

    @mezbahZ React Native Metro সার্ভারে CVE-2025-11953 দুর্বলতা সম্পর্কে আলোচনা করছি। এখানে মূল বিষয়গুলি: #CVE2025 #ReactNative

    Post summary

    The post only states that a discussion of CVE‑2025‑11953 on the React Native Metro server is underway, with no additional technical or actionable information.

    2000047
    317 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appreact-native-communityreact_native_community_cli---
Appreact-native-communityreact_native_community_cli18.0.0--
Appreact-native-communityreact_native_community_cli20.0.0--
Appreact-native-communityreact_native_community_cli20.0.0--
Appreact-native-communityreact_native_community_cli20.0.0--

Explore more