#open-npm

[ follow ]
Information security
fromInfoWorld
2 days ago

RCE in React Native CLI opens Dev Servers to attacks

The Metro development server exposes an unsafe /open-url endpoint and defaults to listening on 0.0.0.0, allowing remote command execution unless patched.
[ Load more ]