logo

CVE-2025-11953 (Metro4Shell) in React Native Metro Server Enables RCE

ID: 9d5c46f0-fd8d-5b9a-a986-da3e12bae302

STIX ID: report--9d5c46f0-fd8d-5b9a-a986-da3e12bae302

Feed Name: SOCRadar Blog

Threat Score
78/100

Date Published: 2026-02-04

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

A critical remote code execution vulnerability (CVE-2025-11953, “Metro4Shell”, CVSS 9.8) in the React Native Community CLI Metro development server allows unauthenticated OS command execution via the /open-url POST endpoint when Metro is reachable beyond localhost. The issue affects @react-native-community/cli-server-api (versions approximately 4.8.0 through 20.0.0-alpha.2) and has confirmed in-the-wild exploitation observed in late December 2025 and January 2026; mitigations include upgrading to patched versions (>=18.0.1/19.1.2/20.0.0+), binding Metro to 127.0.0.1, and restricting network access to developer and CI hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.