Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-11953-POC- — CVE-2025-11953 is a critical Remote Code Execution (RCE) vulnerability in the React Native CLI's Metro development server | Kitploit
Tools/GitHubGitHub/mr-in4inci3le/cve-2025-11953-poc-
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and ControlLearning & Education
GitHubmr-in4inci3le/cve-2025-11953-poc-

CVE-2025-11953-POC-

CVE-2025-11953 is a critical Remote Code Execution (RCE) vulnerability in the React Native CLI's Metro development server

View Repository
28 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-11953 - React Native CLI RCE Research Environment

Security Vulnerability CVSS Platform

📋 Overview

CVE-2025-11953 is a critical Remote Code Execution (RCE) vulnerability in the React Native CLI's Metro development server discovered by JFrog Security. This research environment provides the actual vulnerable implementation for defensive security research, detection development, and mitigation testing.

CVSS Score: 9.8 (CRITICAL)
Affected Versions: @react-native-community/cli-server-api v4.8.0 – v20.0.0-alpha.2
Fixed Version: v20.0.0+ (Released October 2025)
Vulnerability Type: OS Command Injection via /open-url endpoint
Weekly Downloads: Over 2 million (pre-disclosure)

🚀 Quick Start

Prerequisites

  • Windows 10/11 VM (recommended for realistic testing)
  • Node.js 14.0 or higher
  • ISOLATED Virtual Machine (mandatory - no bridged networking)
  • Disabled Windows Defender/antivirus for testing
  • No connection to production networks

Installation

# Clone the repository
git clone <repository-url>
cd <directory>

# Install dependencies
npm install

# Start the app
npm start

# Localhost only
npm run start-local

DEMO Screenshots

image
Download Tool