Software supply chain security firm JFrog has disclosed the details of a critical vulnerability affecting a popular React ...
Cybersecurity researchers from JFrog say the package in question is called “@react-native-community/cli”, made to help ...
The vulnerability, tracked as CVE-2025-11953, carries a CVSS score of 9.8 out of a maximum of 10.0, indicating critical severity. It also affects the "@react-native-community/cli-server-api" package ...