Skip to content

Niel3D Marketplace

Menu
  • politics
  • general
  • entertainment
  • sports
  • technology
  • business
  • News
  • international relations
  • culture
  • law
Menu

JFrog discloses CVSS 9.8 React vulnerability putting millions of developers at risk

Posted on 2025 年 11 月 4 日 by admin

Security researchers at software supply chain company JFrog Ltd. have revealed details of a critical vulnerability in React, the open-source JavaScript library developed by Meta Platforms Inc., that potentially puts millions of developers at risk of remote code execution.

The JFrog Security Research team discovered the vulnerability in the widely used @react-native-community/cli NPM package, which is downloaded more than 2 million times weekly. Tracked as CVE-2025-11953, this flaw carries a critical Common Vulnerability Scoring System (CVSS) score of 9.8.

When exploited, the vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on machines running the React Native development server (Metro). This can lead to serious compromises in developer environments.

The root of the issue lies within React Native’s core codebase, specifically exposing the server to external networks—even when development servers are deployed locally. This makes the risk associated with the vulnerability particularly severe.

The vulnerability stems from unsafe handling of user-supplied input in the CLI’s /open-url endpoint, which passes unsanitized data to the `open` function from the NPM package open. While the issue primarily affects Windows—enabling attackers to run arbitrary shell commands such as launching `calc.exe`—in theory, macOS and Linux installations could also be vulnerable.

Meta was notified of the vulnerability prior to JFrog’s public disclosure, and patches have since been released. The flaw impacts @react-native-community/cli-server-api versions 4.8.0 through 20.0.0-alpha.2. A fix is included in version 20.0.0 and later.

Developers unsure about the version of React they are using can check their projects by running the following commands:

“`
npm list @react-native-community/cli-server-api
npm list -g @react-native-community/cli-server-api
“`

For those unable to update immediately, JFrog’s researchers recommend mitigating the risk by explicitly binding the development server to localhost using this command:

“`
npx react-native start –host 127.0.0.1
“`

The researchers emphasized the broader implications of this vulnerability, stating:

“This vulnerability shows that even straightforward Remote Code Execution flaws, such as passing user input to the system shell, are still found in real-world software, especially in cases where the dangerous sink function actually resides in third-party code, which was the imported ‘open’ function in this case. It’s a reminder that secure coding practices and automated security scanning are essential for preventing these easily exploitable flaws before they make it to production.”

![React Vulnerability](Image URL here)

*Image: SiliconANGLE/Ideogram*
https://siliconangle.com/2025/11/04/jfrog-discloses-cvss-9-8-react-vulnerability-putting-millions-developers-risk/

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

近期文章

  • Superbon says Masaaki Noiri’s finish of Tawanchai proves he’s really dangerous: “I cannot take him for granted”
  • Dick Cheney Lived Without a Pulse. Literally.
  • Bob Dylan Doesn’t Endorse Politicians, But Zohran Mamdani Has Used “The Times They Are A-Changin’” Anyway
  • Dallas Cowboys acquire linebacker Logan Wilson to bolster NFL’s second-worst defense
  • Bybit x Block Scholes Report: Cautious Crypto Derivatives, WLFI Volatility Persists

近期评论

No comments to show.
LINE下载 LINE官网
wps office下载 wps office官网
whatsapp网页版下载 whatsapp网页版官网
快连下载 快连官网
Zoom下载 Zoom官网
有道翻译下载 有道翻译官网
雷电模拟器下载 雷电模拟器官网
爱思助手下载 爱思助手官网
winrar下载 winrar官网
7-zip下载 7-zip官网
旺商聊下载 旺商聊下载
telegram中文版下载 telegram中文版官网
钉钉下载 钉钉官网
signal下载 signal官网
discord下载 discord官网
雷电模拟器 雷电模拟器电脑版
viber download install viber app
telegram中文版 telegram中文版下载
爱思助手 爱思助手下载
winrar压缩包 winrar解压缩
贝锐向日葵官网 向日葵远程控制
safew官网 safew安卓版
搜狗输入法官网 搜狗输入法下载
line免费电话 line Web版
imtoken官网 imtoken钱包
whatsapp官网 whatsapp网页版
wpsoffice办公软件 wpsoffice免费版
有道翻译官网 有道在线翻译
Google浏览器安卓版 Google浏览器官方最新版
企业微信 企业微信官网
whatsapp 网页版 whatsapp web
WPS官网 WPS Office
丝瓜聊天 丝瓜聊天下载
谷歌浏览器 谷歌浏览器官网
快连 VPN LetsVPN
Anydesk下载 Anydesk官网
safew 官网 safew 下载
向日葵官网 向日葵远程控制
zoom官网 zoom在线会议
搜狗输入法 搜狗输入法官网
雷电模拟器 雷电模拟器官网
LINE官网 LINE下载
有道翻译 有道翻译官网
telegram中文版官网 telegram中文版下载
百度网盘 百度网盘下载
豆包ai 豆包官网
搜狗输入法下载 搜狗输入法
rar解压 zip解压软件
wps下载 wps办公软件
wps中文版 wps官网
网易有道翻译下载 有道翻译官网
whatsapp 网页版 whatsapp web
tokenpocket官网 TP钱包下载
汽水音乐网页版 汽水音乐下载
© 2025 Niel3D Marketplace | Powered by Superbs Personal Blog theme
Friendly links
  • LINE下载
  • LINE官网
  • wps office下载
  • wps office官网
  • 快连下载
  • 快连官网
  • Zoom下载
  • Zoom官网
  • 有道翻译下载
  • 有道翻译官网
  • 雷电模拟器下载
  • 雷电模拟器官网
  • 爱思助手下载
  • 爱思助手官网
  • winrar下载
  • winrar官网
  • 旺商聊
  • 旺商聊下载
  • 钉钉下载
  • 钉钉官网
  • signal下载
  • signal官网
  • discord下载
  • discord官网
  • whatsapp 网页版
  • whatsapp web
  • 雷电模拟器
  • 雷电模拟器电脑版
  • viber
  • viber app
  • 爱思助手
  • 爱思助手下载
  • winrar压缩包
  • winrar解压缩
  • 向日葵官网
  • 向日葵远程控制
  • safew官网
  • safew
  • 搜狗输入法官网
  • 搜狗输入法
  • line
  • line官网
  • imtoken官网
  • imtoken钱包
  • wps office官网
  • wps soffice
  • 有道翻译官网
  • 有道翻译
  • Google浏览器
  • Google chrome浏览器
  • 企业微信
  • 企业微信官网
  • WPS官网
  • WPS Office
  • 丝瓜聊天
  • 丝瓜聊天下载
  • 谷歌浏览器
  • 谷歌浏览器官网
  • 快连 VPN
  • LetsVPN
  • Anydesk下载
  • Anydesk官网
  • safew 官网
  • safew 下载
  • 向日葵官网
  • 向日葵远程控制
  • zoom官网
  • zoom在线会议
  • 搜狗输入法
  • 搜狗输入法官网
  • 雷电模拟器
  • 雷电模拟器官网
  • LINE官网
  • LINE下载
  • 百度网盘
  • 百度网盘下载
  • 豆包ai
  • 豆包官网
  • 搜狗输入法下载
  • 搜狗输入法
  • rar解压
  • zip解压软件
  • wps下载
  • wps办公软件
  • wps office官网
  • wps官网
  • 网易有道翻译下载
  • 有道翻译官网
  • tokenpocket官网
  • TP钱包下载
  • 汽水音乐网页版
  • 汽水音乐下载
  • whatsapp 网页版
  • whatsapp web
  • 有道翻译
  • 有道翻译官网
  • Telegram中文版下载
  • Telegram中文版官网
  • Telegram中文版
  • Telegram中文版官网
  • Telegram中文版
  • 纸飞机中文版
  • LINE官网
  • LINE官方中文网站
  • WhatsApp网页版
  • WhatsApp官网
  • Telegram中文版官网
  • Telegram中文版
  • WPS
  • 谷歌浏览器
  • WPS