
CVE-2025-11953 is a critical Remote Code Execution (RCE) vulnerability in the React Native CLI's Metro development server
CVE-2025-11953 is a critical Remote Code Execution (RCE) vulnerability in the React Native CLI's Metro development server discovered by JFrog Security. This research environment provides the actual vulnerable implementation for defensive security research, detection development, and mitigation testing.
CVSS Score: 9.8 (CRITICAL)
Affected Versions: @react-native-community/cli-server-api v4.8.0 – v20.0.0-alpha.2
Fixed Version: v20.0.0+ (Released October 2025)
Vulnerability Type: OS Command Injection via /open-url endpoint
Weekly Downloads: Over 2 million (pre-disclosure)
# Clone the repository
git clone <repository-url>
cd <directory>
# Install dependencies
npm install
# Start the app
npm start
# Localhost only
npm run start-local
