Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

NBA star Giannis Antetokounmpo joins Calci as an investor

New York state lawmaker proposes three-year moratorium on new data centers

This week’s science news: Anomalies inside Earth, the Artemis II leak and how psychedelics can help treat PTSD

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Critical flaw in React Native CLI leaves millions of developers open to remote attacks
Identity

Critical flaw in React Native CLI leaves millions of developers open to remote attacks

userBy userNovember 4, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

November 4, 2025Ravi LakshmananVulnerabilities / Supply Chain Security

Details have emerged about a critical security flaw that was patched in the popular @react-native-community/cli npm package. This flaw can be exploited under certain conditions to execute malicious operating system (OS) commands.

“This vulnerability allows an unauthenticated, remote attacker to easily cause execution of arbitrary OS commands on the machine running the react-native-community/cli development server, posing a significant risk to developers,” Or Peles, senior security researcher at JFrog, said in a report shared with The Hacker News.

DFIR retainer service

This vulnerability is tracked as CVE-2025-11953 and has a CVSS score of 9.8 out of a maximum of 10.0, indicating critical severity. It also affects versions 4.8.0 through 20.0.0-alpha.2 of the “@react-native-community/cli-server-api” package, which was patched in version 20.0.0 released early last month.

Command-line tool packages maintained by Meta allow developers to build React Native mobile applications. It receives approximately 1.5 to 2 million downloads each week.

According to the software supply chain security firm, the vulnerability arises from the fact that the Metro development server that React Native uses to build JavaScript code and assets is bound by default to an external interface (rather than localhost) and exposes an “/open-url” endpoint that is susceptible to OS command injection.

“The server’s ‘/open-url’ endpoint handles POST requests containing user input values ​​that are passed to the insecure open() function provided by the open NPM package, which executes OS commands,” Perez said.

As a result, an unauthenticated network attacker could exploit this flaw to execute arbitrary commands by sending specially crafted POST requests to the server. On Windows, an attacker can also execute arbitrary shell commands with fully controlled arguments, while on Linux and macOS it can be exploited to execute arbitrary binaries with limited parameter control.

CIS build kit

This issue has since been resolved, but developers using React Native with frameworks that do not rely on Metro as their development server are not affected.

“This zero-day vulnerability is particularly dangerous due to its ease of exploitation, lack of authentication requirements, and wide attack surface,” Perez said. “It also exposes significant risks hidden in third-party code.”

“For developers and security teams, this highlights the need for automated and comprehensive security scanning across the software supply chain to ensure easily exploitable flaws are remediated before they impact the organization.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleA bug in Microsoft Teams allows attackers to impersonate colleagues and edit messages without their knowledge
Next Article WhatsApp releases long-awaited Apple Watch app
user
  • Website

Related Posts

Warning of signal phishing targeting German government agencies, politicians, military personnel and journalists

February 7, 2026

The Legal Revolution is Digital: Meet TwinH, Your AI Partner in the Courtroom of the Future

February 6, 2026

China-linked DKnife AitM framework, routers targeted for traffic hijacking and malware distribution

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

NBA star Giannis Antetokounmpo joins Calci as an investor

New York state lawmaker proposes three-year moratorium on new data centers

This week’s science news: Anomalies inside Earth, the Artemis II leak and how psychedelics can help treat PTSD

Warning of signal phishing targeting German government agencies, politicians, military personnel and journalists

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.