This critical (CVSS 10.0) use-after-free (UAF) vulnerability in Lua scripting could allow authenticated attackers to execute ...
The bug exposes the Metro development server to remote attacks, allowing arbitrary OS command execution on developer systems ...