Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-11953 PoC — Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP

Source
Associated Vulnerability
Title: Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests (CVE-2025-11953)
Description:The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.
Description
CVE-2025-11953 demonstration: Critical RCE vulnerability in React Native CLI (CVSS 9.8). Educational security research with proof-of-concept exploits and mitigation strategies.
Readme
# React Native CLI Command Injection Demo (CVE-2025-11953)

## ⚠️ VULNERABILITY DEMONSTRATION ⚠️

**JFSA-2025-001495618** - Critical Command Injection in React Native CLI

- **CVE**: CVE-2025-11953
- **CVSS Score**: 9.8 (Critical)
- **Affected Package**: @react-native-community/cli-server-api
- **Vulnerable Versions**: [4.8.0, 20.0.0)
- **Discovery**: JFrog Security Research Team

## Vulnerability Summary

The Metro Development Server, which is opened by the React Native CLI, binds to external interfaces by default. The server exposes an endpoint (`/open-url`) that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables.

### Impact
- **Remote Code Execution (RCE)**
- **Command Injection**
- **No Authentication Required**
- **Network Accessible**

## Demo Structure

```
react-native-cli-command-injection-demo/
├── README.md                    # This file
├── vulnerable-setup/
│   ├── package.json            # Vulnerable version setup
│   ├── metro.config.js         # Metro configuration
│   └── start-vulnerable.js     # Script to start vulnerable server
├── exploit-examples/
│   ├── basic-exploit.sh        # Basic command injection example
│   ├── windows-exploit.sh      # Windows-specific exploit
│   ├── advanced-exploit.py     # Advanced exploitation script
│   └── payload-examples.json   # Various payload examples
├── secure-setup/
│   ├── package.json            # Fixed version setup
│   ├── metro.config.js         # Secure configuration
│   └── start-secure.js         # Secure server startup
└── mitigation/
    ├── SECURITY.md             # Security recommendations
    └── host-binding-examples.sh # Host binding examples
```

## Quick Start

### 1. Setup Vulnerable Environment
```bash
cd vulnerable-setup
npm install
npm run start:vulnerable
```

### 2. Run Exploit
```bash
cd exploit-examples
./basic-exploit.sh
```

### 3. Setup Secure Environment
```bash
cd secure-setup
npm install
npm run start:secure
```

## ⚠️ IMPORTANT SECURITY NOTICE

This demonstration is for educational purposes only. Do not use these examples in production environments or against systems you do not own. Always follow responsible disclosure practices.

## Links

- [JFrog Vulnerability Report](https://research.jfrog.com/vulnerabilities/react-native-cli-command-injection-jfsa-2025-001495618/)
- [JFrog Technical Blog](https://jfrog.com/blog/cve-2025-11953-critical-react-native-community-cli-vulnerability)
- [Fix Commit](https://github.com/react-native-community/cli/commit/15089907d1f1301b22c72d7f68846a2ef20df547)
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →