CVE-2025-11953 (Metro4Shell) in React Native Metro Server Enables RCE
ID: 9d5c46f0-fd8d-5b9a-a986-da3e12bae302
STIX ID: report--9d5c46f0-fd8d-5b9a-a986-da3e12bae302
Feed Name: SOCRadar Blog
A critical remote code execution vulnerability (CVE-2025-11953, “Metro4Shell”, CVSS 9.8) in the React Native Community CLI Metro development server allows unauthenticated OS command execution via the /open-url POST endpoint when Metro is reachable beyond localhost. The issue affects @react-native-community/cli-server-api (versions approximately 4.8.0 through 20.0.0-alpha.2) and has confirmed in-the-wild exploitation observed in late December 2025 and January 2026; mitigations include upgrading to patched versions (>=18.0.1/19.1.2/20.0.0+), binding Metro to 127.0.0.1, and restricting network access to developer and CI hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
