A critical vulnerability in the popular expr-eval JavaScript library, with over 800,000 weekly downloads on NPM, can be ...
The vulnerability, tracked as CVE-2025-11953, carries a CVSS score of 9.8 out of a maximum of 10.0, indicating critical severity. It also affects the "@react-native-community/cli-server-api" package ...
A widely popular npm package carried a critical severity vulnerability that allowed threat actors to, in certain scenarios, ...
The bug exposes the Metro development server to remote attacks, allowing arbitrary OS command execution on developer systems ...