Hackers Exploiting React Native’s Metro Server in the Wild to Attack Developers

Hackers are actively exploiting a critical remote code execution vulnerability (CVE-2025-11953) in React Native’s Metro Development Server to deliver malware on Windows and Linux systems. The vulnerability, dubbed Metro4Shell, stems from an OS command injection flaw in the /open-url endpoint and has a critical CVSS score of 9.8, yet exploitation is occurring before widespread public awareness.

Edward Kiledjian @ekiledjian