logo

CISA Warns of React Native Community Command Injection Vulnerability Exploited in Attacks

ID: 2d7892de-ba19-54bb-a039-42bb3961add8

STIX ID: report--2d7892de-ba19-54bb-a039-42bb3961add8

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-02-06

Date Updated: 2026-04-21

Author: Guru Baran

...
...

CISA added CVE-2025-11953 — an OS command injection in the React Native Community CLI — to its Known Exploited Vulnerabilities catalog, warning that unauthenticated POST requests against exposed Metro development servers can achieve remote code execution (including full shell control on Windows) and enable ransomware, data exfiltration, or persistent backdoors; the report urges immediate patching, firewalling of Metro ports, EDR/command-line monitoring, and hunting for anomalous POSTs and unexpected process spawns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.