Teegra 🧝♀️𝕏[verified]@TeeegraActive Exploitation
CVE‑2025‑11953 is being actively exploited via a PowerShell‑based RCE in the npm package; attacks have been documented and added to CISA’s KEV list, but no patch or workaround has been mentioned.
Nur[verified]@winxf1perisiActive Exploitation
CVE-2025-11953 (Metro4Shell) in the React Native Metro dev server has been actively exploited since December 2025, with attacks continuing as of February 2026.
SOCRadar®[verified]@socradarActive Exploitation
CVE‑2025‑11953, dubbed Metro4Shell, is an unauthenticated RCE in the React Native Metro Server with a CVSS score of 9.8, and attackers are currently exploiting it in developer environments and CI pipelines.
中島佑允(YusukeNakajima)[verified]@nakajimeeeeActive Exploitation
VulnCheck reports that CVE‑2025‑11953 (Metro4Shell) is actively exploited in the wild, with attackers using a Base64‑encoded PowerShell payload to download a Rust binary and bypass Windows Defender. The vulnerability, rated CVSS 9.8, remains largely unpublicized.
piyokango[verified]@piyokangoActive Exploitation
CISA has added two CVEs to its Known Exploited Vulnerabilities catalog, confirming real‑world exploitation—especially in ransomware incidents—while no PoC or exploit code and no patch information are explicitly shared.
kokumօtօ[verified]@__kokumotoActive Exploitation
CVE-2025-11953, dubbed "Metro4Shell", is being actively exploited in the wild as reported by VulnCheck.
Averlon[verified]@Averlon_aiDisclosure
The post announces a high‑severity command‑injection vulnerability (CVE‑2025‑11953) in React Native CLI, outlines steps for assessing relevance and remediation, and directs readers to a blog for further vulnerability context.
DataHogo[verified]@DataHogoDisclosure
The post discloses CVE-2025-11953, a critical RCE in the React Native dev server that allows unauthenticated execution of commands over the network, with no current patch or exploit code referenced.