Skip to content
CISA Known Exploited Vulnerability

CVE-2025-11953 — React Actively Exploited CVE

React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary ex

⚠ Actively exploited (CISA KEV) React 2025
CISA catalog entry
Product
CLI
Vendor
React Native Community
Added to KEV
2026-02-05
Remediation due
2026-02-26

CVE-2025-11953 is tracked in the CISA Known Exploited Vulnerabilities catalog. WebPulse monitors it as part of its framework security intelligence.

View CVE-2025-11953 on the NIST National Vulnerability Database →