Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

Millions of developers could be open to attack after critical flaw exploited – here’s what we know

Tech Wavo by Tech Wavo
November 5, 2025
in Computers
0



  • CVE-2025-11953 allows OS command injection via Metro server in React Native CLI
  • Affects versions 4.8.0–20.0.0-alpha.2; patched in 20.0.0; exploit requires no authentication
  • No confirmed exploitation yet; restrict server exposure or update immediately

A widely popular npm package carried a critical severity vulnerability that allowed threat actors to, in certain scenarios, run malicious commands, experts have warned.

Cybersecurity researchers from JFrog say the package in question is called “@react-native-community/cli”, made to help developers build React Native mobile applications, and getting up to two million downloads a week.

On NVD, it is explained the Metro Development Server, opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint vulnerable to OS command injection, allowing threat actors to send a POST request and run arbitrary executables – meaning on Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments, and on Linux and macOS, on the other hand, it can execute arbitrary binaries with limited parameter control.


You may like

Acting like hacktivists

The bug is tracked as CVE-2025-11953, and has a severity score of 9.8/10 (critical). It affects package versions 4.8.0 through 20.0.0-alpha.2, and has been patched in version 20.0.0 released early last month. Those that cannot immediately update their endpoints should restrict network exposure of the Metro server.

If you are using React Native with a framework that doesn’t rely on Metro as a development server, you are not affected, it was further stated. “This zero day vulnerability is particularly dangerous due to its ease of exploitation, lack of authentication requirements and broad attack surface,” JFrog’s researchers explained. “It also exposes the critical risks hidden in third-party code.”

“For developer and security teams, this underscores the need for automated, comprehensive security scanning across the software supply chain to ensure easily exploitable flaws are remediated before they impact your organization.”

At press time, there were no confirmed public reports that CVE‑2025‑11953 had been exploited in the wild. Multiple sources indicate that while the vulnerability is highly exploitable, actual exploit activity hasn’t yet been verified.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Via The Hacker News


Best antivirus software header

The best antivirus for all budgets

Our top picks, based on real-world testing and comparisons

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Previous Post

These are the Black Friday tech deals I want to see in 2025

Next Post

The best early tech deals on Apple, Shark, Lego and other gear ahead of the biggest sale of the year

Next Post
The best early tech deals on Apple, Shark, Lego and other gear ahead of the biggest sale of the year

The best early tech deals on Apple, Shark, Lego and other gear ahead of the biggest sale of the year

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Driving Honda’s lighter, faster and more fun next-gen hybrid prototype

by Tech Wavo
November 5, 2025
0
Computers

With the American market still struggling to get its head around the whole electric car thing, plenty of manufacturers are...

Read more

Sony’s ‘Cross-Buy’ PS5 symbol leaks, hinting at PC crossover similar to ‘Xbox Play Anywhere’ – and I’m hoping Rockstar considers this for GTA 6

by Tech Wavo
November 5, 2025
0
Sony’s ‘Cross-Buy’ PS5 symbol leaks, hinting at PC crossover similar to ‘Xbox Play Anywhere’ – and I’m hoping Rockstar considers this for GTA 6
Computers

Leaked PS5 symbols hint at Sony's potential plans for a big PS5 to PC crossover'Cross-Buy' suggests Sony may replicate Microsoft's...

Read more

Co-op game Overcooked may become a competition reality TV show on Netflix

by Tech Wavo
November 5, 2025
0
Co-op game Overcooked may become a competition reality TV show on Netflix
Computers

Hilarious co-op video game Overcooked is making the move to the real world. A24 has acquired the rights to the...

Read more

The 5 hottest electric motorcycles from the EICMA 2025 show

by Tech Wavo
November 5, 2025
0
The 5 hottest electric motorcycles from the EICMA 2025 show
Computers

Harley's LiveWire drops the big bikes for small, fun stuffZero Motorcycles enters the cheap scooter marketHonda goes electric without the...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock