Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-11953

Опубликовано: 03 нояб. 2025
Источник: redhat
CVSS3: 8.1
EPSS Критический

Описание

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

A command injection flaw has been discovered in the npm @react-native-community/cli-server-api package. URLs are not properly validated which may allow an attacker to execute local code which is already present on the host.

Отчет

The complexity of exploitation on Linux is significantly higher than on Windows as the attacker may only trigger executable which have been pre-installed and which are accessible to the affected program.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2412025@react-native-community/cli-server-api: Command injection in React Native CLI

EPSS

Процентиль: 100%
0.9398
Критический

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
10 месяцев назад

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

CVSS3: 9.8
github
10 месяцев назад

@react-native-community/cli has arbitrary OS command injection

CVSS3: 9.8
fstec
около 1 года назад

Уязвимость сервера для разработки Metro Development Server, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 100%
0.9398
Критический

8.1 High

CVSS3