Story perspectives
Critical Vulnerability Discovered in Popular React Native Package
11/5/2025
27 3
1 of 1
Story summary
- JFrog identifies a critical remote code execution vulnerability, CVE-2025-11953, in the @react-native-community/cli NPM package with nearly two million weekly downloads.
- The flaw allows unauthenticated attackers to execute arbitrary commands on developers' machines via the Metro server.
- The vulnerability has a CVSS score of 9.8 and affects versions 4.8.0 through 20.0.0-alpha.2.
- Meta released a patch in version 20.0.0; developers should update immediately or bind the server to localhost.
