1 link tagged with all of: vulnerability + exploits + security + npm + react-native
Links
A serious security vulnerability in the "@react-native-community/cli" npm package allowed attackers to execute arbitrary OS commands on development servers. The flaw, tracked as CVE-2025-11953, was patched in version 20.0.0 after being discovered by JFrog's security team. Developers using affected versions are at risk if they run the Metro development server.
react-native ✓
security ✓
vulnerability ✓
npm ✓
exploits ✓