CVE-2025-11953 — React-native-community React Native Community Cli
CISA KEVAs of 2026-02-06, CVE-2025-11953 is a CRITICAL-severity vulnerability in React-native-community React Native Community Cli, CVSS v3.1 9.8, EPSS 11.5% (93.6th percentile). It is listed in the CISA Known Exploited Vulnerabilities catalog (added 2026-02-05), with a US federal remediation deadline of 2026-02-26. Threadlinqs Intelligence links 2 tracked threat campaigns to CVE-2025-11953, most recently “P2Pinfect Kubernetes Compromise — Exposed Redis Enables Persistent GKE Botnet Enrollment with Six-Month Dormancy (CVE-2022-0543, CVE-2025-11953, CVE-2025-49844)”.
Last updated: 2026-02-06
What is CVE-2025-11953?
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.
The record classifies CVE-2025-11953 under weakness class CWE-78. Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs no prior authentication, needs no user interaction, and has high impact on confidentiality, integrity, availability. 5 affected-product entries are recorded, across 1 vendor, listed below. The identifier was first published 314 days ago.
Severity and exploitation probability
- CVSS v3.1 base score
- 9.8 — CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS (FIRST)
- 11.5% probability of exploitation in the next 30 days, higher than 93.6% of all scored CVEs
- CISA KEV
- Listed since 2026-02-05, federal remediation deadline 2026-02-26
- Threadlinqs priority
- 9/10 — CISA KEV-listed, which Threadlinqs floors at 9
- Published
- 2025-11-03, last modified 2026-02-06
Is CVE-2025-11953 being exploited?
CISA added CVE-2025-11953 to the Known Exploited Vulnerabilities catalog on 2026-02-05, which means the agency holds evidence of exploitation in the wild; US federal civilian agencies had to remediate it by 2026-02-26 under BOD 22-01. It currently carries a trending score of 38 in the Threadlinqs vulnerability feed.
Affected products and versions
- React-native-community: React Native Community Cli, React Native Community Cli 18.0.0, React Native Community Cli 20.0.0
Showing 3 of 5 recorded product entries.
How to fix CVE-2025-11953
The record marks a vendor fix as available for CVE-2025-11953. Patch reference: https://github.com/react-native-community/cli/commit/15089907d1f1301b22c72d7f68846a2ef20df547. Vendor advisory: https://github.com/react-native-community/cli/commit/15089907d1f1301b22c72d7f68846a2ef20df547. Because CVE-2025-11953 is KEV-listed, US federal civilian agencies were required to apply the vendor fix, or stop using the product, by 2026-02-26. Apply the vendor fix referenced above to every affected product listed in this record, then confirm the running version against the vendor advisory.
Threat activity tracking CVE-2025-11953
2 tracked threats in the Threadlinqs corpus reference CVE-2025-11953, either in the campaign’s CVE list or as an indicator on the campaign record.
- P2Pinfect Kubernetes Compromise — Exposed Redis Enables Persistent GKE Botnet Enrollment with Six-Month Dormancy (CVE-2022-0543, CVE-2025-11953, CVE-2025-49844) — HIGH · 2026-05-21
- Critical React Native Vulnerability Actively Exploited in the Wild — CRITICAL · 2026-02-03
Sources
Seeded from nvd and not yet processed by the Threadlinqs enrichment pipeline, so blank CVSS, EPSS or KEV fields above mean NOT MEASURED rather than measured-absent.
← all vulnerabilities · Markdown version · Threadlinqs Intelligence