Skip to content

Conversation

@aikido-autofix
Copy link

@aikido-autofix aikido-autofix bot commented Dec 5, 2025

Upgrading @react-native-community/cli to address vulnerabilities.

🚨 1 CVE resolved by this upgrade, including 1 critical CVE

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2025-10854
🚨 CRITICAL
Affected versions of the React Native Community CLI expose a Metro development server that binds to external interfaces and provides an endpoint vulnerable to OS command injection, allowing unauthenticated remote attackers to issue crafted POST requests that execute arbitrary executables. On Windows...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant