The vulnerability, tracked as CVE-2025-11953, carries a CVSS score of 9.8 out of a maximum of 10.0, indicating critical severity. It also affects the "@react-native-community/cli-server-api" package ...
Software supply chain security firm JFrog has disclosed the details of a critical vulnerability affecting a popular React ...
Security researchers at software supply chain company JFrog Ltd. today revealed details of a critical vulnerability in React, ...
The security research team at JFrog, a provider of a platform for building and deploying software, have discovered a critical vulnerability in a node ...
Cybersecurity researchers from JFrog say the package in question is called “@react-native-community/cli”, made to help ...
The bug exposes the Metro development server to remote attacks, allowing arbitrary OS command execution on developer systems ...