top of page
Suspicious Activity?


Metro4Shell (CVE-2025-11953): RCE in React Native Dev Server
A critical Remote Code Execution vulnerability has been discovered in the Metro Development Server used in React Native development environments, and recent attack activity has been observed exploiting this flaw to distribute malicious payloads. The vulnerability, tracked as CVE-2025-11953 and referred to as Metro4Shell, originates from an OS Command Injection issue in the /open-url endpoint, which is provided for development convenience. This issue is particularly noteworthy

Yoshi Lee
1 day ago2 min read
Subscribe to the PAGO Newsletter
bottom of page
