Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2025-11953

10 месяцев назад

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

CVSS3: 8.1
EPSS: Критический
nvd логотип

CVE-2025-11953

10 месяцев назад

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-399j-vxmf-hjvr

10 месяцев назад

@react-native-community/cli has arbitrary OS command injection

CVSS3: 9.8
EPSS: Критический
fstec логотип

BDU:2026-01467

около 1 года назад

Уязвимость сервера для разработки Metro Development Server, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-11953

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

CVSS3: 8.1
94%
Критический
10 месяцев назад
nvd логотип
CVE-2025-11953

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

CVSS3: 9.8
94%
Критический
10 месяцев назад
github логотип
GHSA-399j-vxmf-hjvr

@react-native-community/cli has arbitrary OS command injection

CVSS3: 9.8
94%
Критический
10 месяцев назад
fstec логотип
BDU:2026-01467

Уязвимость сервера для разработки Metro Development Server, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
94%
Критический
около 1 года назад

Уязвимостей на страницу