CISA Warns of React Native Community Command Injection Vulnerability Exploited in Attacks
ID: 2d7892de-ba19-54bb-a039-42bb3961add8
STIX ID: report--2d7892de-ba19-54bb-a039-42bb3961add8
Feed Name: cybersecurityNews.com
CISA added CVE-2025-11953 — an OS command injection in the React Native Community CLI — to its Known Exploited Vulnerabilities catalog, warning that unauthenticated POST requests against exposed Metro development servers can achieve remote code execution (including full shell control on Windows) and enable ransomware, data exfiltration, or persistent backdoors; the report urges immediate patching, firewalling of Metro ports, EDR/command-line monitoring, and hunting for anomalous POSTs and unexpected process spawns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
