{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2025-11953",
  "revision": 1,
  "title": "React Native Community CLI — development server command injection",
  "summary": "The Metro development server opened by the React Native command line tool (CLI) listens on external interfaces and exposes an endpoint that runs programs named in the request, so anyone on the network can execute code on a developer's machine.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.9398,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2026-02-05",
    "prerequisites": "Network reach to a running Metro development server; no credentials needed."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1059"
  ],
  "kill_chain": "execution",
  "recommended_action": "Upgrade the React Native Community command line tool now; bind the development server to localhost and keep developer machines off shared networks.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2025-11953",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2025-11953",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2025-11953",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11953",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://github.com/react-native-community/cli/commit/15089907d1f1301b22c72d7f68846a2ef20df547"
    },
    {
      "type": "exploit",
      "url": "https://jfrog.com/blog/cve-2025-11953-critical-react-native-community-cli-vulnerability"
    },
    {
      "type": "exploit",
      "url": "https://www.vulncheck.com/blog/metro4shell_eitw"
    }
  ],
  "published_at": "2025-11-03T17:15:32.677Z",
  "issued_at": "2026-09-24T08:51:39.744Z",
  "tags": [
    "react-native",
    "metro",
    "developer-tooling",
    "command-injection",
    "kev"
  ]
}
