CVE-2025-11953 demonstration: Critical RCE vulnerability in React Native CLI (CVSS 9.8). Educational security research with proof-of-concept exploits and mitigation strategies.
# React Native CLI Command Injection Demo (CVE-2025-11953)
## ⚠️ VULNERABILITY DEMONSTRATION ⚠️
**JFSA-2025-001495618** - Critical Command Injection in React Native CLI
- **CVE**: CVE-2025-11953
- **CVSS Score**: 9.8 (Critical)
- **Affected Package**: @react-native-community/cli-server-api
- **Vulnerable Versions**: [4.8.0, 20.0.0)
- **Discovery**: JFrog Security Research Team
## Vulnerability Summary
The Metro Development Server, which is opened by the React Native CLI, binds to external interfaces by default. The server exposes an endpoint (`/open-url`) that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables.
### Impact
- **Remote Code Execution (RCE)**
- **Command Injection**
- **No Authentication Required**
- **Network Accessible**
## Demo Structure
```
react-native-cli-command-injection-demo/
├── README.md # This file
├── vulnerable-setup/
│ ├── package.json # Vulnerable version setup
│ ├── metro.config.js # Metro configuration
│ └── start-vulnerable.js # Script to start vulnerable server
├── exploit-examples/
│ ├── basic-exploit.sh # Basic command injection example
│ ├── windows-exploit.sh # Windows-specific exploit
│ ├── advanced-exploit.py # Advanced exploitation script
│ └── payload-examples.json # Various payload examples
├── secure-setup/
│ ├── package.json # Fixed version setup
│ ├── metro.config.js # Secure configuration
│ └── start-secure.js # Secure server startup
└── mitigation/
├── SECURITY.md # Security recommendations
└── host-binding-examples.sh # Host binding examples
```
## Quick Start
### 1. Setup Vulnerable Environment
```bash
cd vulnerable-setup
npm install
npm run start:vulnerable
```
### 2. Run Exploit
```bash
cd exploit-examples
./basic-exploit.sh
```
### 3. Setup Secure Environment
```bash
cd secure-setup
npm install
npm run start:secure
```
## ⚠️ IMPORTANT SECURITY NOTICE
This demonstration is for educational purposes only. Do not use these examples in production environments or against systems you do not own. Always follow responsible disclosure practices.
## Links
- [JFrog Vulnerability Report](https://research.jfrog.com/vulnerabilities/react-native-cli-command-injection-jfsa-2025-001495618/)
- [JFrog Technical Blog](https://jfrog.com/blog/cve-2025-11953-critical-react-native-community-cli-vulnerability)
- [Fix Commit](https://github.com/react-native-community/cli/commit/15089907d1f1301b22c72d7f68846a2ef20df547)
登录后查看神龙缓存的 POC 文件快照
登录查看