Skip to content

Niel3D Marketplace

Menu
  • politics
  • general
  • entertainment
  • sports
  • technology
  • business
  • News
  • international relations
  • culture
  • law
Menu

JFrog discloses CVSS 9.8 React vulnerability putting millions of developers at risk

Posted on 2025 年 11 月 4 日 by admin

Security researchers at software supply chain company JFrog Ltd. have revealed details of a critical vulnerability in React, the open-source JavaScript library developed by Meta Platforms Inc., that potentially puts millions of developers at risk of remote code execution.

The JFrog Security Research team discovered the vulnerability in the widely used @react-native-community/cli NPM package, which is downloaded more than 2 million times weekly. Tracked as CVE-2025-11953, this flaw carries a critical Common Vulnerability Scoring System (CVSS) score of 9.8.

When exploited, the vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on machines running the React Native development server (Metro). This can lead to serious compromises in developer environments.

The root of the issue lies within React Native’s core codebase, specifically exposing the server to external networks—even when development servers are deployed locally. This makes the risk associated with the vulnerability particularly severe.

The vulnerability stems from unsafe handling of user-supplied input in the CLI’s /open-url endpoint, which passes unsanitized data to the `open` function from the NPM package open. While the issue primarily affects Windows—enabling attackers to run arbitrary shell commands such as launching `calc.exe`—in theory, macOS and Linux installations could also be vulnerable.

Meta was notified of the vulnerability prior to JFrog’s public disclosure, and patches have since been released. The flaw impacts @react-native-community/cli-server-api versions 4.8.0 through 20.0.0-alpha.2. A fix is included in version 20.0.0 and later.

Developers unsure about the version of React they are using can check their projects by running the following commands:

“`
npm list @react-native-community/cli-server-api
npm list -g @react-native-community/cli-server-api
“`

For those unable to update immediately, JFrog’s researchers recommend mitigating the risk by explicitly binding the development server to localhost using this command:

“`
npx react-native start –host 127.0.0.1
“`

The researchers emphasized the broader implications of this vulnerability, stating:

“This vulnerability shows that even straightforward Remote Code Execution flaws, such as passing user input to the system shell, are still found in real-world software, especially in cases where the dangerous sink function actually resides in third-party code, which was the imported ‘open’ function in this case. It’s a reminder that secure coding practices and automated security scanning are essential for preventing these easily exploitable flaws before they make it to production.”

![React Vulnerability](Image URL here)

*Image: SiliconANGLE/Ideogram*
https://siliconangle.com/2025/11/04/jfrog-discloses-cvss-9-8-react-vulnerability-putting-millions-developers-risk/

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RSS The New York Times

  • U.S. Military Threat Puts Spotlight on Venezuela’s Allies 2025 年 11 月 18 日 Anatoly Kurmanaev
  • Meta Did Not Violate Antitrust Law, Judge Rules 2025 年 11 月 18 日 Cecilia Kang
  • Trump Team Calls Maduro a ‘Cartel’ Boss. That Word Doesn’t Mean What You Think. 2025 年 11 月 18 日 Charlie Savage
  • Cloudflare Outage Disrupts X, ChatGPT and Other Parts of the Internet 2025 年 11 月 18 日 Victor Mather
  • Trump Family’s Business Ties to Saudi Arabia Raise Ethics Worries 2025 年 11 月 18 日 Vivian Nereim
  • Larry Summers to Step Back From Public Commitments Over Epstein Emails 2025 年 11 月 18 日 Vimal Patel
  • UN Support Propels Trump Gaza Plan, but Road Ahead Is Still Rough 2025 年 11 月 18 日 David M. Halbfinger
  • Ecuador Votes ‘No’ to Hosting U.S. Military Base 2025 年 11 月 18 日 Genevieve Glatsky and José María León Cabrera
  • Google Unveils Gemini 3, With Improved Coding and Search Abilities 2025 年 11 月 18 日 Tripp Mickle and Cade Metz
  • Palestinian Voices Absent from U.S.-Run Center Planning Gaza’s Future 2025 年 11 月 18 日 Aaron Boxerman, Adam Rasgon, Natan Odenheimer and David M. Halbfinger
  • House Democrats Press for Vote to Bar Military Action in Venezuela 2025 年 11 月 18 日 Robert Jimison
  • U.S. Fraud Case Against Indian Tycoon Adani at a Standstill 2025 年 11 月 18 日 Alex Travelli and Santul Nerkar
  • New York City’s Scaffolding Gets a Long Overdue Makeover 2025 年 11 月 18 日 Winnie Hu
  • The Growing Cost of Keeping Close Ties with Jeffrey Epstein 2025 年 11 月 18 日 Andrew Ross Sorkin, Bernhard Warner, Sarah Kessler, Michael J. de la Merced, Niko Gallogly and Brian O’Keefe
  • With Trump in Office, a Transgender Trailblazer and American Diplomat Seeks Refuge Abroad 2025 年 11 月 18 日 Ernesto Londoño and Erin Schaff

近期文章

  • Saudi Prince MBS Pledges to Invest $1 Trillion in US
  • Congress Prepares To Continue Doing Nothing After Shutdown Ends
  • Chuck Schumer Malfunctions When Pressed on Biden Hiding the Epstein Files for Years [WATCH]
  • Neo-Nazi leader admits plot to give poisoned candy to Jewish kids in New York City
  • NBA Makes Decision on Potential Draymond Green Punishment After Fan Incident

近期评论

No comments to show.
© 2025 Niel3D Marketplace | Powered by Superbs Personal Blog theme
友情链接
纸飞机中文版 | Zoom官网 | Telegram中文版官网 | 丝瓜聊天下载 | 有道翻译 | LINE官网 | 有道翻译下载 | 搜狗输入法官网 | 爱思助手下载 | 百度网盘下载