Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaw in Popular React Native NPM Package Exposes Developers to Attacks

Critical Flaw in Popular React Native NPM Package Exposes Developers to Attacks

Posted on November 4, 2025November 4, 2025 By CWS

Software program provide chain safety agency JFrog has disclosed the main points of a vital vulnerability affecting a well-liked React Native NPM package deal.

React Native is an open supply framework designed for creating purposes that work throughout cell, desktop and net platforms. 

The vulnerability found by JFrog researchers, tracked as CVE-2025-11953 and assigned a CVSS rating of 9.8, impacts the React Native Group CLI NPM package deal (@react-native-community/cli), which offers command-line instruments for constructing apps and which has roughly two million downloads each week. 

In line with JFrog, CVE-2025-11953 can put builders in danger, enabling unauthenticated risk actors to execute arbitrary instructions with attacker-controlled parameters by means of POST requests despatched to the focused server.

“Not like typical vulnerabilities in improvement servers which are solely exploitable from a developer’s native machine, a second safety difficulty that the staff noticed in React Native’s core codebase, exposes the event server to exterior community assaults – making the previous vulnerability a extremely vital difficulty,” JFrog warned.

Researchers managed to take advantage of the vulnerability on Home windows for arbitrary OS command execution with full parameter management. On Linux and macOS, the researchers achieved code execution with restricted parameter management, however they consider the vulnerability might have the next impression on these platforms as nicely. 

JFrog identified that the flaw is simply exploitable in opposition to builders who use a susceptible model of the NPM package deal and depend on the Metro improvement server.

The safety agency stated the vulnerability was shortly patched by Meta, which is the unique developer of React Native and which continues to be concerned in its upkeep alongside a big open supply neighborhood and company contributors similar to Microsoft. Commercial. Scroll to proceed studying.

A patch for CVE-2025-11953 is included in model 20.0.0. Customers have been suggested to replace @react-native-community/cli-server-api to this model or increased in every of their initiatives. 

Associated: Shai-Hulud Provide Chain Assault: Worm Used to Steal Secrets and techniques, 180+ NPM Packages Hit

Associated: 136 NPM Packages Delivering Infostealers Downloaded 100,000 Instances

Associated: NPM Infrastructure Abused in Phishing Marketing campaign Geared toward Industrial and Electronics Companies

Security Week News Tags:Attacks, Critical, Developers, Exposes, Flaw, Native, NPM, Package, Popular, React

Post navigation

Previous Post: Europol and Eurojust Dismantle €600 Million Crypto Fraud Network in Global Sweep
Next Post: Critical RCE Vulnerability in Popular React Native NPM Package Exposes Developers to Attacks

Related Posts

Recent 7-Zip Vulnerability Exploited in Attacks Recent 7-Zip Vulnerability Exploited in Attacks Security Week News
GreyNoise Flags 9,000 ASUS Routers Backdoored Via Patched Vulnerability GreyNoise Flags 9,000 ASUS Routers Backdoored Via Patched Vulnerability Security Week News
Dutch Authorities Arrest Bulletproof Hosting Admins Linked to Russia Dutch Authorities Arrest Bulletproof Hosting Admins Linked to Russia Security Week News
Law Firms Warned of Silent Ransom Group Attacks Law Firms Warned of Silent Ransom Group Attacks Security Week News
Oracle EBS Cyberattack: Silence from Four Major Firms Oracle EBS Cyberattack: Silence from Four Major Firms Security Week News
Oracle Responds to PeopleSoft Security Threat Amid Hacker Attacks Oracle Responds to PeopleSoft Security Threat Amid Hacker Attacks Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark