Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Softbank’s sale of NVIDIA causes market confusion and questions arise

WhatsApp malware ‘Maverick’ hijacks browser sessions and targets Brazil’s largest banks

GootLoader is back, uses new font tricks to hide malware on WordPress sites

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Critical flaw in React Native CLI leaves millions of developers open to remote attacks
Identity

Critical flaw in React Native CLI leaves millions of developers open to remote attacks

userBy userNovember 4, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

November 4, 2025Ravi LakshmananVulnerabilities / Supply Chain Security

Details have emerged about a critical security flaw that was patched in the popular @react-native-community/cli npm package. This flaw can be exploited under certain conditions to execute malicious operating system (OS) commands.

“This vulnerability allows an unauthenticated, remote attacker to easily cause execution of arbitrary OS commands on the machine running the react-native-community/cli development server, posing a significant risk to developers,” Or Peles, senior security researcher at JFrog, said in a report shared with The Hacker News.

DFIR retainer service

This vulnerability is tracked as CVE-2025-11953 and has a CVSS score of 9.8 out of a maximum of 10.0, indicating critical severity. It also affects versions 4.8.0 through 20.0.0-alpha.2 of the “@react-native-community/cli-server-api” package, which was patched in version 20.0.0 released early last month.

Command-line tool packages maintained by Meta allow developers to build React Native mobile applications. It receives approximately 1.5 to 2 million downloads each week.

According to the software supply chain security firm, the vulnerability arises from the fact that the Metro development server that React Native uses to build JavaScript code and assets is bound by default to an external interface (rather than localhost) and exposes an “/open-url” endpoint that is susceptible to OS command injection.

“The server’s ‘/open-url’ endpoint handles POST requests containing user input values ​​that are passed to the insecure open() function provided by the open NPM package, which executes OS commands,” Perez said.

As a result, an unauthenticated network attacker could exploit this flaw to execute arbitrary commands by sending specially crafted POST requests to the server. On Windows, an attacker can also execute arbitrary shell commands with fully controlled arguments, while on Linux and macOS it can be exploited to execute arbitrary binaries with limited parameter control.

CIS build kit

This issue has since been resolved, but developers using React Native with frameworks that do not rely on Metro as their development server are not affected.

“This zero-day vulnerability is particularly dangerous due to its ease of exploitation, lack of authentication requirements, and wide attack surface,” Perez said. “It also exposes significant risks hidden in third-party code.”

“For developers and security teams, this highlights the need for automated and comprehensive security scanning across the software supply chain to ensure easily exploitable flaws are remediated before they impact the organization.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleA bug in Microsoft Teams allows attackers to impersonate colleagues and edit messages without their knowledge
Next Article WhatsApp releases long-awaited Apple Watch app
user
  • Website

Related Posts

WhatsApp malware ‘Maverick’ hijacks browser sessions and targets Brazil’s largest banks

November 11, 2025

GootLoader is back, uses new font tricks to hide malware on WordPress sites

November 11, 2025

CISO’s expert guide to AI supply chain attacks

November 11, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Softbank’s sale of NVIDIA causes market confusion and questions arise

WhatsApp malware ‘Maverick’ hijacks browser sessions and targets Brazil’s largest banks

GootLoader is back, uses new font tricks to hide malware on WordPress sites

Switzerland joins major research program with Horizon Europe

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Meet Your Digital Twin: Europe’s Cutting-Edge AI is Personalizing Medicine

TwinH: The AI Game-Changer for Faster, More Accessible Legal Services

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.