๐Ÿ” CVE Alert

CVE-2026-97366

MEDIUM 6.3

jhen0409 react-native-debugger Open in Editor window.js openDevTools os command injection

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/window.js of the component Open in Editor Handler. The manipulation of the argument host results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CWE CWE-78 CWE-77
Vendor jhen0409
Product react-native-debugger
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for jhen0409 react-native-debugger

Be the first to know when new medium vulnerabilities affecting jhen0409 react-native-debugger are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

jhen0409 / react-native-debugger
0.1 0.2 0.3 0.4 0.5 0.6 0.7 0.8 0.9 0.10 0.11 0.12 0.13 0.14.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/409351 vuldb.com: https://vuldb.com/vuln/409351/cti vuldb.com: https://vuldb.com/cve/CVE-2026-97366 vuldb.com: https://vuldb.com/submit/909329 gist.github.com: https://gist.github.com/Suuuuuzy/d25baf1973fd3c812277e02cde2243cc

Credits

๐Ÿ” Jianjia Yu (VulDB User) VulDB CNA Team