Hackers Exploit CVE-2025-11953 in React Native Metro to Breach Developer Systems
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Hackers are actively exploiting the critical vulnerability CVE-2025-11953 in the Metro server for React Native, which is essential for building and running applications during development. This vulnerability allows attackers to execute arbitrary OS commands on Windows through unauthenticated POST requests, while on Linux and macOS, it can lead to running arbitrary executables with limited control over parameters. Discovered by researchers at JFrog in early November 2025, the flaw affects @react-native-community/cli-server-api versions 4.8.0 through 20.0.0-alpha.2 and was patched in version 20.0.0 and later.
On December 21, 2025, VulnCheck reported that threat actors began exploiting CVE-2025-11953, dubbed Metro4Shell. The exploitation has continued into January 2026, with researchers observing the same base-64 encoded PowerShell payloads being delivered in the malicious requests targeting exposed endpoints. The attacks have demonstrated a practical, cross-platform initial access mechanism, affecting both Windows and Linux systems.
Understanding the Exploit Mechanism
In the attacks, the payloads perform several actions, including disabling endpoint protections by adding exclusion paths for Microsoft Defender, establishing a TCP connection to retrieve the next-stage payload, and executing the downloaded binary. The Windows payload is a Rust-based UPX-packed binary, while a corresponding Linux binary has also been identified, indicating the attacks are not limited to one platform.
Despite the ongoing exploitation, the vulnerability still carries a low score in the Exploit Prediction Scoring System (EPSS), which estimates the likelihood of exploitation for security issues. Researchers emphasize that organizations should not wait for official alerts or vendor reports before taking action to secure their systems.
With approximately 3,500 exposed React Native Metro servers identified online, developers and organizations must prioritize securing these systems to prevent unauthorized access and potential data breaches. The presence of multiple proof-of-concept exploits further underscores the urgency of addressing this vulnerability.
- CVE-2025-11953: A critical vulnerability in the Metro server for React Native that allows attackers to execute arbitrary commands.
- Metro4Shell: The name given to the exploitation of CVE-2025-11953, affecting both Windows and Linux platforms.
- JFrog: The software supply-chain security company that discovered and disclosed the vulnerability.
- VulnCheck: The vulnerability intelligence company that reported on the active exploitation of CVE-2025-11953.
- Microsoft Defender: A security feature that can be bypassed by the exploit, allowing attackers to disable protections.
Key Takeaways
- Check if your React Native Metro server is running an affected version and update to 20.0.0 or later.
- Monitor your systems for any signs of unauthorized access or unusual activity related to CVE-2025-11953.
- Implement network segmentation to limit exposure of development servers to external networks.
- Review and enhance endpoint protection settings to prevent exploitation of vulnerabilities.
- Stay informed about security updates and advisories from trusted sources regarding vulnerabilities like CVE-2025-11953.
Key Terms & Concepts
- CVE-2025-11953: In this article, CVE-2025-11953 refers to a critical vulnerability in the Metro server for React Native that allows unauthorized command execution.
- Metro4Shell: Metro4Shell is the name given to the exploitation of the CVE-2025-11953 vulnerability, affecting both Windows and Linux systems.
- JFrog: JFrog is a software supply-chain security company that discovered and disclosed the CVE-2025-11953 vulnerability.
- VulnCheck: VulnCheck is a vulnerability intelligence company that reported on the active exploitation of CVE-2025-11953.
- Microsoft Defender: Microsoft Defender is a security feature that can be bypassed by the exploit, allowing attackers to disable protections.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.