Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
I. Basic Information for CVE-2025-11953
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
Source: NVD (National Vulnerability Database)
Vulnerability Description
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: NVD (National Vulnerability Database)
Vulnerability Title
React Native Community CLI 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
React Native Community CLI是React Native Community开源的一个命令行工具。 React Native Community CLI存在安全漏洞,该漏洞源于默认绑定外部接口且端点存在OS命令注入漏洞,可能导致未经验证的攻击者发送POST请求执行任意命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
II. Public POCs for CVE-2025-11953
#POC DescriptionSource LinkShenlong Link
1CVE-2025-11953 demonstration: Critical RCE vulnerability in React Native CLI (CVSS 9.8). Educational security research with proof-of-concept exploits and mitigation strategies.https://github.com/SaidBenaissa/cve-2025-11953-vulnerability-demoPOC Details
2CVE-2025-11953https://github.com/B1ack4sh/Blackash-CVE-2025-11953POC Details
3Comprehensive Proof of Concept collection for CVE-2025-11953, CVE-2025-59287, CVE-2025-8941 with exploitation frameworks in Python, C, Bash, PowerShellhttps://github.com/N3k0t-dev/PoC-CVE-collectionPOC Details
4CVE-2025-11953https://github.com/Ashwesker/Blackash-CVE-2025-11953POC Details
5Nonehttps://github.com/Mr-In4inci3le/CVE-2025-11953-POC-POC Details
6Nonehttps://github.com/boroeurnprach/CVE-2025-11953-PoCPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2025-11953
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2025-11953

No comments yet


Leave a comment