Microsoft’s TypeScript language is approaching its 2.2 release with an emphasis on support for React Native, Facebook’s JavaScript framework for building native mobile apps. The upgrade has moved to a ...
CVE-2025-11953 allows OS command injection via Metro server in React Native CLI Affects versions 4.8.0–20.0.0-alpha.2; patched in 20.0.0; exploit requires no authentication No confirmed exploitation ...
The bug exposes the Metro development server to remote attacks, allowing arbitrary OS command execution on developer systems before a fix in version 20.0.0. A critical remote-code execution (RCE) flaw ...