
Reproducer for CVE-2023-3635 in Okio 2.9.0, demonstrating how React Native's version catalog pins a vulnerable dependency, affecting Android apps.
Reproducer for facebook/react-native#58148:
React Native's own packages/react-native/gradle/libs.versions.toml pins okhttp = "4.9.2" /
okio = "2.9.0", and okio 2.9.0 is affected by
CVE-2023-3635 / GHSA-w33c-445m-f8w7,
fixed in okio 3.4.0.
No app code was edited to produce this. ReproducerApp is the completely unmodified output
of npx @react-native-community/cli init, generated against [email protected] (this template's
current latest, matching main's 0.87.0-main). The vulnerable pin comes from React Native's own
version catalog, not from anything a consuming app does.
To reproduce, from ReproducerApp/android:
./gradlew :app:dependencies --configuration releaseRuntimeClasspath | grep -iE "okhttp|okio"
Output (full run saved in gradle-dependencies-output.txt):
com.squareup.okhttp3:okhttp-urlconnection:4.9.2
com.squareup.okhttp3:okhttp:4.9.2 (*)
com.squareup.okio:okio:2.9.0 (*)
com.squareup.okhttp3:okhttp:3.14.9 -> 4.9.2
com.squareup.okio:okio:2.8.0 -> 2.9.0
okhttp/okio land on the app's actual shipped releaseRuntimeClasspath (not just test tooling),
pulled in transitively via com.facebook.fresco:imagepipeline-okhttp3 and React Native's own
react-android artifact.
This is your new React Native Reproducer project.
This project has been created with npx @react-native-community/cli init and is a vanilla React Native app.
[!IMPORTANT]
Make sure you have completed the React Native - Environment Setup so that you have a working environment locally.
First, you will need to start Metro, the JavaScript bundler that ships with React Native.
To start Metro, run the following command from the root of your React Native project:
# using npm
npm start
# OR using Yarn
yarn start
Let Metro Bundler run in its own terminal. Open a new terminal from the root of your React Native project. Run the following command to start your Android or iOS app:
# using npm
npm run android
# OR using Yarn
yarn android
First, make sure you install dependencies with:
cd ios && bundle install && bundle exec pod install
Then you can run the iOS app with:
# using npm
npm run ios
# OR using Yarn
yarn ios
If everything is set up correctly, you should see your new app running in your Android Emulator or iOS Simulator shortly provided you have set up your emulator/simulator correctly.
This is one way to run your app — you can also run it directly from within Android Studio and Xcode respectively.
Now that you have successfully run the app, let's modify it.
Open App.tsx in your text editor of choice and edit some lines.
For Android: Press the R key twice or select "Reload" from the Developer Menu (Ctrl + M (on Window and Linux) or Cmd ⌘ + M (on macOS)) to see your changes!
For iOS: Hit Cmd ⌘ + R in your iOS Simulator to reload the app and see your changes!