The bug exposes the Metro development server to remote attacks, allowing arbitrary OS command execution on developer systems before a fix in version 20.0.0. A critical remote-code execution (RCE) flaw ...
CVE-2025-11953 allows OS command injection via Metro server in React Native CLI Affects versions 4.8.0–20.0.0-alpha.2; patched in 20.0.0; exploit requires no authentication No confirmed exploitation ...
Unlock the full InfoQ experience by logging in! Stay updated with your favorite authors and topics, engage with content, and download exclusive resources. Vivek Yadav, an engineering manager from ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results