← Global Threat Landscape
CVE-2025-11953
CWE-78
Critical
103.7
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.
Source: NVD
Signals
- CVSS
- 9.8
- Critical · v3.1
- EPSS
- 93.98%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since Feb 2026
- Fix commit
- No known fix commit
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-78
- Published
- 3 Nov 2025
- Last modified 6 Feb 2026
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2025-11953Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time