The vulnerability, tracked as CVE-2025-11953, carries a CVSS score of 9.8 out of a maximum of 10.0, indicating critical severity. It also affects the "@react-native-community/cli-server-api" package ...
The bug exposes the Metro development server to remote attacks, allowing arbitrary OS command execution on developer systems ...
5don MSN
Millions of developers could be open to attack after critical flaw exploited - here's what we know
Cybersecurity researchers from JFrog say the package in question is called “@react-native-community/cli”, made to help ...
Results that may be inaccessible to you are currently showing.
Hide inaccessible results