Categories: Cyber Security News

CISA Warns of React Native Community Command Injection Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-11953 to its Known Exploited Vulnerabilities (KEV) catalog, flagging an OS command injection flaw in the React Native Community CLI as actively exploited in the wild.

Added on February 5, 2026, with a federal patching deadline of February 26, 2026, the vulnerability poses severe risks to developers running exposed Metro Development Servers.

React Native, a popular framework for cross-platform mobile apps used by enterprises like Meta and Shopify, relies on the Community CLI for project management and Metro bundler for fast bundling.

Attackers can exploit a vulnerable endpoint by sending unauthenticated POST requests and executing arbitrary executables remotely. On Windows, this escalates to full control of the shell with attacker-specified arguments, enabling ransomware deployment, data exfiltration, or persistent backdoors.

This open-source flaw could ripple through third-party libraries and proprietary apps, amplifying supply chain risks. No ransomware attribution yet, but threat actors favor such dev-tool vulns for initial access in APT campaigns.

Enterprises with CI/CD pipelines or dev environments face elevated threats. Exposed Metro servers—common in local dev workflows—allow lateral movement if chained with weak network segmentation. SOC teams should hunt for anomalous POSTs to CLI endpoints (e.g., /cli/debugger) and IOCs like unexpected process spawns.

  • Immediate Patch: Update CLI via GitHub fixes; verify with npx @react-native-community/cli@latest doctor.
  • Follow BOD 22-01: Harden cloud services (AWS, Azure) with least-privilege access.
  • Defenses: Firewall Metro ports (8081 default); use EDR for command-line monitoring; discontinue unpatched use.
  • Hunt Queries: Sigma rules for cmd.exe /c with CLI args or Metro traffic spikes.

CISA urges FCEB agencies to act swiftly. Developers: Never expose dev servers publicly. This serves as a reminder: dev tools are prime targets in the expansion of 2026’s attack surface.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

The post CISA Warns of React Native Community Command Injection Vulnerability Exploited in Attacks appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Free activities galore at UMass Founders Day 2026 event

AMHERST — Performances by local and student bands, an art walk at campus galleries and…

24 minutes ago

Community Legal Aid gets grant to help seal eviction cases

GREENFIELD — Aided by grant funding, the nonprofit law organization providing free services to low-income…

24 minutes ago

Area Briefs: Children’s Advocacy Center luminaria event

Children’s Advocacy Center luminaria event NORTHAMPTON — The Children’s Advocacy Center (CAC) of Hampshire County…

24 minutes ago

Chesterfield appoints new Council on Aging director

CHESTERFIELD — For the fourth time in 16 months, Chesterfield has a new Council on…

24 minutes ago

Pluralistic: Ada Palmer’s “Inventing the Renaissance” (25 Apr 2026)

Today's links Ada Palmer's "Inventing the Renaissance": A tour-de-force, a magnum opus, a work of…

5 hours ago

This Week’s Awesome Tech Stories From Around the Web (Through April 25)

Future The People Do Not Yearn for AutomationNilay Patel | The Verge “Not everything about…

6 hours ago

This website uses cookies.