Hackers Exploit CVE-2025-11953 in React Native Metro to Breach Developer Systems
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Hackers are actively exploiting the critical vulnerability CVE-2025-11953 in the Metro server used by React Native, which is essential for building applications. Discovered by JFrog in early November 2025, this flaw allows attackers to execute arbitrary commands on Windows systems via unauthenticated POST requests. On Linux and macOS, the vulnerability can lead to executing arbitrary executables with limited control over parameters.
The vulnerability affects @react-native-community/cli-server-api versions 4.8.0 through 20.0.0-alpha.2, and it was patched in version 20.0.0 and later. Despite the patch, researchers from VulnCheck observed exploitation attempts beginning December 21, 2025, with ongoing attacks noted on January 4 and 21, 2026.
During these attacks, hackers delivered base-64 encoded PowerShell payloads hidden in the HTTP POST body of requests to exposed endpoints. Once executed, these payloads disable endpoint protections, establish connections to attacker-controlled infrastructure, and download further malicious payloads.
Understanding the Risks
Approximately 3,500 React Native Metro servers are exposed online, making them potential targets for attackers. The exploitation of CVE-2025-11953 demonstrates a significant risk for developers who may inadvertently expose their systems during the development phase. The attacks utilize a technique dubbed Metro4Shell, which effectively provides cross-platform access to compromised systems.
Despite the ongoing exploitation, the vulnerability is rated low in the Exploit Prediction Scoring System (EPSS), which may lead organizations to underestimate the risk. Researchers emphasize that organizations should not wait for formal advisories or vendor reports before taking action to secure their systems.
VulnCheck’s report includes indicators of compromise (IoCs) related to the attacker network infrastructure, which can help organizations identify and mitigate potential threats. Developers and organizations using React Native should prioritize updating their systems to the latest version to protect against this vulnerability.
Key Takeaways
- Update React Native Metro to version 20.0.0 or later to mitigate the CVE-2025-11953 vulnerability.
- Regularly scan for exposed Metro servers to identify potential security risks.
- Implement network security measures to restrict access to development-only HTTP endpoints.
- Monitor for unusual activity or unauthorized commands on development systems.
- Review and apply security best practices for software supply chains to reduce exposure to vulnerabilities.
Key Terms & Concepts
- CVE-2025-11953: In this article, CVE-2025-11953 refers to a critical vulnerability in the Metro server for React Native that allows unauthorized command execution.
- Metro server: The Metro server is the default JavaScript bundler for React Native projects, essential for building and running applications.
- PowerShell payloads: PowerShell payloads are scripts executed in the PowerShell environment, often used by attackers to perform malicious actions.
- Indicators of compromise (IoCs): IoCs are pieces of forensic data that identify potentially malicious activity on a system or network.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.