PT-2026-98294 · Unknown · React-Native-Debugger
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
react-native-debugger versions prior to 0.14.1
Description
An OS command injection flaw exists in the Open in Editor Handler component. The issue occurs within the
openDevTools() function located in the electron/window.js file, where improper handling of the host argument allows for remote attack execution.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the
openDevTools() function to minimize the risk of exploitation.Exploit
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
React-Native-Debugger