More

    Millions of developers could be open to attack after critical flaw exploited – here’s what we know



    • CVE-2025-11953 allows OS command injection via Metro server in React Native CLI
    • Affects versions 4.8.0–20.0.0-alpha.2; patched in 20.0.0; exploit requires no authentication
    • No confirmed exploitation yet; restrict server exposure or update immediately

    A widely popular npm package carried a critical severity vulnerability that allowed threat actors to, in certain scenarios, run malicious commands, experts have warned.

    Cybersecurity researchers from JFrog say the package in question is called “@react-native-community/cli”, made to help developers build React Native mobile applications, and getting up to two million downloads a week.


    https://cdn.mos.cms.futurecdn.net/UNBhCvCBZ47GpjzV7AN5mG-970-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img