Vulnerability GHSA-g9g6-gvq9-j4vp
High Risk
HIGH RISK
CVSS Score: 7.3
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 months ago
July 06, 2026 at 09:30 AM UTC
react-dev-utils openBrowser permits command injection on macOS
0.0.0 - 5.0.1
0.0.0 - 5.0.1
Summary
react-dev-utils openBrowser permits command injection on macOS
Details
A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
5 years ago
react-dev-utils OS Command Injection in function `getProcessForPort`
0.4.0 - 11.0.3 GHSA-5q6m-3h65-w53x
0.4.0 - 11.0.3 GHSA-5q6m-3h65-w53x
High Risk
7 years ago
react-dev-utils on Windows vulnerable to Remote Code Execution
1.0.0 - 1.0.3 and 2.0.0 - 2.0.1 and 3.0.0 - 3.1.1 and 4.0.0 - 4.2.1 and 5.0.0 - 5.0.1 GHSA-29gp-92wp-94q8
1.0.0 - 1.0.3 and 2.0.0 - 2.0.1 and 3.0.0 - 3.1.1 and 4.0.0 - 4.2.1 and 5.0.0 - 5.0.1 GHSA-29gp-92wp-94q8
Impacted packages
Timeline
Published
2 months ago
July 06, 2026 at 09:30 AM UTC
Last Modified
5 hours ago
October 01, 2026 at 09:15 PM UTC