All verified exploits

CVE-2025-11953 Metro Dev Server Command Injection via /open-url

Deterministic critical Metro CISA KEV Added cve-verified-cve-2025-11953

Detects exposed React Native Metro Development Servers where the /open-url endpoint passes user-supplied URLs to the OS open handler without validation. An unauthenticated network attacker can execute arbitrary commands on the developer's machine. Affects @react-native-community/cli-server-api versions 4.8.0 through 20.0.0-alpha.2.

Is your app exploitable through CVE-2025-11953?

Scan your domain free