Intel

AIKIDO-2025-10854

@react-native-community/cli is vulnerable to Command Injection

Command InjectionCVE-2025-11953 Published Dec 1, 2025

98

Critical Risk

This Affects:

JS@react-native-community/cli
0.0.1 - 17.0.0
Fixed in 17.0.1
18.0.0 - 18.0.0
Fixed in 18.0.1
19.0.0 - 19.1.1
Fixed in 19.1.2
Are you affected? Scan for Free

TL;DR

Affected versions of the React Native Community CLI expose a Metro development server that binds to external interfaces and provides an endpoint vulnerable to OS command injection, allowing unauthenticated remote attackers to issue crafted POST requests that execute arbitrary executables. On Windows, attackers can further run arbitrary shell commands with fully controlled arguments.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@react-native-community/cli is vulnerable to Command Injection in versions 0.0.1 - 17.0.0, 18.0.0 - 18.0.0 and 19.0.0 - 19.1.1.

How to fix this

Upgrade the @react-native-community/cli and @react-native-community/cli-server-api library to the patch version.