Vulnerability GHSA-g9g6-gvq9-j4vp

High Risk
HIGH RISK
CVSS Score: 7.3
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 months ago
July 06, 2026 at 09:30 AM UTC
react-dev-utils openBrowser permits command injection on macOS
0.0.0 - 5.0.1
0.0.0 - 5.0.1

Summary

react-dev-utils openBrowser permits command injection on macOS

Details

A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Impacted packages

Timeline

Published
2 months ago
July 06, 2026 at 09:30 AM UTC
Last Modified
5 hours ago
October 01, 2026 at 09:15 PM UTC