Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Feb 26, 2026

CVE-2025-11953

High
EPSS 3.4%CISA KEV

Description

React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a vulnerable endpoint exposed by the server. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments.

EPSS — Exploit Probability

3.4%

Higher than 87.2% of all CVEs

Required Action

This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/react-native-community/cli/commit/15089907d1f1301b22c72d7f68846a2ef20df547 ; https://github.com/react-native-community/cli/pull/2735 ; https://nvd.nist.gov/vuln/detail/CVE-2025-11953

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
3.4%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Feb 5, 2026

Added to KEV

Feb 5, 2026

Remediation Due

Feb 26, 2026

Affected Product

React Native Community

CLI

View all React Native Community CVEs