Drooid Logo
Back to today’s briefing

Story perspectives

Critical Vulnerability Discovered in Popular React Native Package

11/5/2025

27 3

1 of 1

Story summary
  • JFrog identifies a critical remote code execution vulnerability, CVE-2025-11953, in the @react-native-community/cli NPM package with nearly two million weekly downloads.
  • The flaw allows unauthenticated attackers to execute arbitrary commands on developers' machines via the Metro server.
  • The vulnerability has a CVSS score of 9.8 and affects versions 4.8.0 through 20.0.0-alpha.2.
  • Meta released a patch in version 20.0.0; developers should update immediately or bind the server to localhost.