Skip to content

Niel3D Marketplace

Menu
  • politics
  • general
  • entertainment
  • sports
  • technology
  • business
  • News
  • international relations
  • culture
  • law
Menu

JFrog discloses CVSS 9.8 React vulnerability putting millions of developers at risk

Posted on 2025 年 11 月 4 日 by admin

Security researchers at software supply chain company JFrog Ltd. have revealed details of a critical vulnerability in React, the open-source JavaScript library developed by Meta Platforms Inc., that potentially puts millions of developers at risk of remote code execution.

The JFrog Security Research team discovered the vulnerability in the widely used @react-native-community/cli NPM package, which is downloaded more than 2 million times weekly. Tracked as CVE-2025-11953, this flaw carries a critical Common Vulnerability Scoring System (CVSS) score of 9.8.

When exploited, the vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on machines running the React Native development server (Metro). This can lead to serious compromises in developer environments.

The root of the issue lies within React Native’s core codebase, specifically exposing the server to external networks—even when development servers are deployed locally. This makes the risk associated with the vulnerability particularly severe.

The vulnerability stems from unsafe handling of user-supplied input in the CLI’s /open-url endpoint, which passes unsanitized data to the `open` function from the NPM package open. While the issue primarily affects Windows—enabling attackers to run arbitrary shell commands such as launching `calc.exe`—in theory, macOS and Linux installations could also be vulnerable.

Meta was notified of the vulnerability prior to JFrog’s public disclosure, and patches have since been released. The flaw impacts @react-native-community/cli-server-api versions 4.8.0 through 20.0.0-alpha.2. A fix is included in version 20.0.0 and later.

Developers unsure about the version of React they are using can check their projects by running the following commands:

“`
npm list @react-native-community/cli-server-api
npm list -g @react-native-community/cli-server-api
“`

For those unable to update immediately, JFrog’s researchers recommend mitigating the risk by explicitly binding the development server to localhost using this command:

“`
npx react-native start –host 127.0.0.1
“`

The researchers emphasized the broader implications of this vulnerability, stating:

“This vulnerability shows that even straightforward Remote Code Execution flaws, such as passing user input to the system shell, are still found in real-world software, especially in cases where the dangerous sink function actually resides in third-party code, which was the imported ‘open’ function in this case. It’s a reminder that secure coding practices and automated security scanning are essential for preventing these easily exploitable flaws before they make it to production.”

![React Vulnerability](Image URL here)

*Image: SiliconANGLE/Ideogram*
https://siliconangle.com/2025/11/04/jfrog-discloses-cvss-9-8-react-vulnerability-putting-millions-developers-risk/

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RSS The New York Times

  • Russia Strikes Ukraine and Signals Resistance to Amended Peace Plan 2025 年 11 月 25 日 Maria Varenikova and Aurelien Breeden
  • Times Analysis Finds Errors in Trump’s Supreme Court Filing That Calls for National Guard in Chicago 2025 年 11 月 25 日 Devon Lum, Mattathias Schwartz, Christoph Koettl and Ainara Tiefenthäler
  • Republicans Fight With Trump’s Team Over Ukraine Talks 2025 年 11 月 25 日 Megan Mineiro
  • An Eritrean Woman Seeking Asylum in Canada Was Almost Deported From the U.S. 2025 年 11 月 25 日 Matina Stevis-Gridneff
  • Vahid Abedini, University of Oklahoma Professor, Released After ICE Detainment 2025 年 11 月 25 日 Mark Arsenault
  • Doctor Critical of Vaccines Quietly Appointed as C.D.C.’s Second in Command 2025 年 11 月 25 日 Apoorva Mandavilli
  • Joan Branson, Richard Branson’s Wife of 35 Years, Has Died 2025 年 11 月 25 日 Christine Hauser
  • New York Leads Effort to Stop Plan That Could Cut Housing for 170,000 2025 年 11 月 25 日 Sarah Maslin Nir
  • Binance Is Sued by Oct. 7 Victims’ Families, Accused of Aiding Terrorism 2025 年 11 月 25 日 Stacy Cowley
  • Trump Administration Is Taking Billions in Stakes in Firms Like Intel 2025 年 11 月 25 日 Ana Swanson
  • Bolsonaro To Start Serving 27-Year Prison Sentence Over Coup Plot 2025 年 11 月 25 日 Ana Ionova
  • 100 Notable Books of 2025 2025 年 11 月 25 日 The New York Times Books Staff
  • U.S. Plans Compounds to House Palestinians in Israeli-Held Half of Gaza 2025 年 11 月 25 日 David M. Halbfinger, Adam Rasgon, Natan Odenheimer and Aaron Boxerman
  • Hamas Says It Returned Body of Another Hostage From Gaza 2025 年 11 月 25 日 Aaron Boxerman
  • Market Volatility Underscores Epic Buildup of Global Risk 2025 年 11 月 25 日 Patricia Cohen

近期文章

  • Rhea Ripley reveals real reason why she wants AJ Lee on her WarGames team
  • A man took two sex workers to an Oakland motel, only to be robbed by five people
  • How to get Ghost Flowers in Ghost of Yotei
  • Steelers Get Unexpected Bad Injury News on Key Rookie Starter
  • Economists Are Shocked, Shocked by Who Is Paying the Tariffs

近期评论

No comments to show.
© 2025 Niel3D Marketplace | Powered by Superbs Personal Blog theme
友情链接
纸飞机中文版 | Zoom官网 | Telegram中文版官网 | 丝瓜聊天下载 | 有道翻译 | LINE官网 | 有道翻译下载 | 搜狗输入法官网 | 爱思助手下载 | 百度网盘下载