OS Command Injection Vulnerability in jhen0409 React Native Debugger
CVE-2026-97366
Key Information:
- Vendor
Jhen0409
- Status
- Vendor
- CVE Published:
- 24 September 2026
Badges
What is CVE-2026-97366?
A vulnerability in jhen0409 React Native Debugger versions up to 0.14.0 allows for OS command injection via the openDevTools function in the electron/window.js file. By manipulating the host argument, an attacker can launch commands on the target system remotely. This exploit has been publicly released, indicating a serious risk for users if not patched. The vendor was notably unresponsive upon disclosure of this vulnerability, highlighting the urgency for users to secure their systems.
Affected Version(s)
react-native-debugger 0.1
react-native-debugger 0.2
react-native-debugger 0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
