Find notable cyber news and cases, enriched with sources, timelines, and signals.

Metro server for React Native command execution flaw (CVE-2025-11953, actively exploited)

Vulnerability
First reported
Last updated
Happening score
H score 50
2 unique sources, 3 articles

Summary

Hide ▲

The Metro server for React Native flaw CVE-2025-11953 is being actively exploited, exposing development servers to command execution and malicious payload delivery. The bug affects @react-native-community/cli-server-api 4.8.0 through 20.0.0-alpha.2 and was fixed in 20.0.0 and later. Observed attacks hit exposed endpoints on Windows and Linux with base-64 encoded PowerShell payloads.

Related Happenings

React2Shell (CVE-2025-55182) mass scanning and exploitation wave

Exploitation Wave
H score89 First: 20.02.2026 23:07 Last: 20.02.2026 23:07 Sources 1

About this happening: CVE-2025-55182 (React2Shell) was publicly disclosed on December 3, 2025 as a CVSS 10 remote code execution flaw in React Server Components. Since then, the vulnera...

React Native Metro servers Metro4Shell exploitation wave (CVE-2025-11953)

Exploitation Wave
H score50 First: 03.02.2026 16:00 Last: 03.02.2026 16:00 Sources 1

How related: On December 21, 2025, vulnerability intelligence company VulnCheck observed a threat actor exploiting CVE-2025-11953, dubbed Metro4Shell.

About this happening: Repeated exploitation of CVE-2025-11953 is hitting exposed React Native Metro servers, creating remote command and payload-delivery risk across a large development-systems...

HPE OneView RondoDox exploitation wave (CVE-2025-37164)

Exploitation Wave
H score59 First: 16.01.2026 11:15 Last: 16.01.2026 11:15 Sources 1

About this happening: RondoDox has driven a large-scale exploitation wave against HPE OneView by targeting CVE-2025-37164, with activity escalating into automated attacks that creat...

DCRat delivered through PowerShell and MSBuild in PHALT#BLYX

Malware Activity
H score23 First: 06.01.2026 14:13 Last: 06.01.2026 14:13 Sources 1

About this happening: SHADOW#REACTOR is a multi-stage Windows malware campaign that uses obfuscated VBS, PowerShell, wscript.exe, MSBuild.exe, and in-memory loaders to stealthil...

GlassWorm malware wave targets macOS developers via malicious extensions

Malware Activity
H score14 First: 01.01.2026 17:18 Last: 01.01.2026 17:18 Sources 1

About this happening: GlassWorm resurfaced in a fourth wave targeting macOS developers through malicious VSCode/OpenVSX extensions and trojanized crypto wallet apps. Koi Security said t...

Latest development: 08.01.2026 23:27

Huntress analyzed December 2025 attacks against VMware ESXi environments in which a compromised SonicWall VPN appliance provided initial access, a compromised Domain Admin account was used to pivot via RDP to domain controllers, and the toolkit deployed MAESTRO (exploit.exe), MyDriver.sys, VSOCKpuppet, and GetShell Plugin (client.exe). Huntress also noted build paths containing simplified Chinese and an English-language README, suggesting a well-resourced developer operating in a Chinese-speaking region.

Timeline

  1. 03.02.2026 16:00 2 articles · 5mo ago

    Metro server for React Native command execution flaw (CVE-2025-11953, actively exploited)

    Initial Disclosure

    Researchers disclosed CVE-2025-11953 in early November after finding that the /open-url endpoint accepted a POSTed URL value that could reach `open()` unsanitized. The affected @react-native-community/cli-server-api builds were 4.8.0 through 20.0.0-alpha.2, with a fix in 20.0.0 and later.

    Show sources
  2. 03.02.2026 16:00 1 articles · 5mo ago

    First observed exploitation of CVE-2025-11953 in Metro Development Server

    Exploitation Observed

    Threat actors exploited CVE-2025-11953 (Metro4Shell) in the Metro Development Server of the @react-native-community/cli npm package on December 21, 2025, enabling remote unauthenticated command execution and payload delivery.

    Show sources