<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — React Native Community</title><description>Actively exploited vulnerabilities affecting React Native Community products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/react-native-community.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-11953 — React Native Community CLI OS Command Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-11953</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-11953</guid><description>React Native Community CLI&apos;s Metro Development Server exposes an endpoint that accepts unauthenticated POST requests, allowing any attacker with network access to run arbitrary executables on the host machine. On Windows systems the risk is compounded, as attackers can also execute arbitrary shell commands with fully controlled arguments. Because this server is commonly run during development, any machine running Metro that is reachable on a shared or exposed network is potentially at risk of full system compromise.</description><pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate><category>React Native Community</category><category>CLI</category></item></channel></rss>