Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
reproducer-okio-cve-2023-3635 — Reproducer for CVE-2023-3635 in Okio 2.9.0, demonstrating how React Native's version catalog pins a vulnerable dependency, affecting Android apps. | Kitploit
Tools/GitHubGitHub/joshuaasmith/reproducer-okio-cve-2023-3635
Android SecurityVulnerability AnalysisMobile SecuritySupply Chain SecurityLearning & Education
GitHubjoshuaasmith/reproducer-okio-cve-2023-3635

reproducer-okio-cve-2023-3635

Reproducer for CVE-2023-3635 in Okio 2.9.0, demonstrating how React Native's version catalog pins a vulnerable dependency, affecting Android apps.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
1 day agoNot yet reviewed

reproducer-okio-cve-2023-3635

Build

What this reproduces

Reproducer for facebook/react-native#58148: React Native's own packages/react-native/gradle/libs.versions.toml pins okhttp = "4.9.2" / okio = "2.9.0", and okio 2.9.0 is affected by CVE-2023-3635 / GHSA-w33c-445m-f8w7, fixed in okio 3.4.0.

No app code was edited to produce this. ReproducerApp is the completely unmodified output of npx @react-native-community/cli init, generated against [email protected] (this template's current latest, matching main's 0.87.0-main). The vulnerable pin comes from React Native's own version catalog, not from anything a consuming app does.

To reproduce, from ReproducerApp/android:

root@kitploit:~
./gradlew :app:dependencies --configuration releaseRuntimeClasspath | grep -iE "okhttp|okio"

Output (full run saved in gradle-dependencies-output.txt):

root@kitploit:~
com.squareup.okhttp3:okhttp-urlconnection:4.9.2
com.squareup.okhttp3:okhttp:4.9.2 (*)
com.squareup.okio:okio:2.9.0 (*)
com.squareup.okhttp3:okhttp:3.14.9 -> 4.9.2
com.squareup.okio:okio:2.8.0 -> 2.9.0

okhttp/okio land on the app's actual shipped releaseRuntimeClasspath (not just test tooling), pulled in transitively via com.facebook.fresco:imagepipeline-okhttp3 and React Native's own react-android artifact.


This is your new React Native Reproducer project.

Reproducer TODO list

  • 1. Create a new reproducer project.
  • 2. Git clone your repository locally.
  • 3. Edit the project to reproduce the failure you're seeing.
  • 4. Push your changes, so that Github Actions can run the CI.
  • 5. Make sure the repository is public and share the link with the issue you reported.

How to use this Reproducer

This project has been created with npx @react-native-community/cli init and is a vanilla React Native app.

[!IMPORTANT]
Make sure you have completed the React Native - Environment Setup so that you have a working environment locally.

Step 1: Start the Metro Server

First, you will need to start Metro, the JavaScript bundler that ships with React Native.

To start Metro, run the following command from the root of your React Native project:

root@kitploit:~
# using npm
npm start

# OR using Yarn
yarn start

Step 2: Start your Application

Let Metro Bundler run in its own terminal. Open a new terminal from the root of your React Native project. Run the following command to start your Android or iOS app:

For Android

root@kitploit:~
# using npm
npm run android

# OR using Yarn
yarn android

For iOS

First, make sure you install dependencies with:

root@kitploit:~
cd ios && bundle install && bundle exec pod install

Then you can run the iOS app with:

root@kitploit:~
# using npm
npm run ios

# OR using Yarn
yarn ios

If everything is set up correctly, you should see your new app running in your Android Emulator or iOS Simulator shortly provided you have set up your emulator/simulator correctly.

This is one way to run your app — you can also run it directly from within Android Studio and Xcode respectively.

Step 3: Modifying your App

Now that you have successfully run the app, let's modify it.

  1. Open App.tsx in your text editor of choice and edit some lines.

  2. For Android: Press the R key twice or select "Reload" from the Developer Menu (Ctrl + M (on Window and Linux) or Cmd ⌘ + M (on macOS)) to see your changes!

    For iOS: Hit Cmd ⌘ + R in your iOS Simulator to reload the app and see your changes!

Download Tool