Critical RCE Vulnerability CVE-2025-11953 Puts React Native Developers at Risk
jfrog.com | research | CVE-2025-11953 | #rce | #supply-chain | #npm | #jfrog | #vulnerability-disclosure | #react-native | #cve-2025-11953
Summary
JFrog discloses CVE-2025-11953 (CVSS 9.8): unauthenticated RCE in the @react-native-community/cli dev server lets attackers run OS commands; a related flaw exposes Metro to network attacks.
- Published
- Collected
Skip to content