「React Native CLI」より開発サーバ「Metro Development Server」を起動した環境において、第三者によるコマンド実行が可能となる脆弱性「CVE-2025-11953」が明らかとなったもの。脆弱性を発見したJFrogが報告した。 サーバ起動時にデフォルトで「React Native ...
The vulnerability, tracked as CVE-2025-11953, carries a CVSS score of 9.8 out of a maximum of 10.0, indicating critical severity. It also affects the "@react-native-community/cli-server-api" package ...
Software supply chain security firm JFrog has disclosed the details of a critical vulnerability affecting a popular React ...
The bug exposes the Metro development server to remote attacks, allowing arbitrary OS command execution on developer systems ...
4 日on MSN
Millions of developers could be open to attack after critical flaw exploited - here's what ...
A widely popular npm package carried a critical severity vulnerability that allowed threat actors to, in certain scenarios, ...
Security researchers at software supply chain company JFrog Ltd. today revealed details of a critical vulnerability in React, ...
A severe vulnerability was discovered in the React Native Community CLI, a popular open-source package downloaded nearly two million times every week by developers building cross-platform applications ...
2025年10月7日、ReactおよびReact NativeがLinux Foundation傘下のReact Foundationに移行することが発表された。 Introducing the React Foundation: The New Home for React & React Native - Engineering at Meta Introducing the React ...
現在アクセス不可の可能性がある結果が表示されています。
アクセス不可の結果を非表示にする