Impact
A flaw in the "openDevTools" function of jhen0409’s react-native-debugger allows an attacker to inject arbitrary OS commands by manipulating the "host" argument. The resulting command injection can lead to execution of commands with the privileges of the electron process, compromising confidentiality, integrity, and availability of the host system. The vulnerability is classified as a command injection weakness (CWE-77) and can lead to operating‑system command execution (CWE-78).
Affected Systems
The vulnerability affects jhen0409’s react-native-debugger package up to and including version 0.14.0. Any deployment using those releases is susceptible. Versions released after 0.14.0 may have addressed the issue, but this is not confirmed by the vendor.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact if exploitation succeeds, yet the publicly released exploit demonstrates that remote attackers can trigger the flaw without additional preconditions. EPSS is currently unavailable and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, via the electron window that accepts the host parameter. Because the issue involves OS command injection, an attacker can potentially gain full control of the underlying operating system if the electron process runs with elevated privileges.
OpenCVE Enrichment