"The Metro development server [..] binds to external interfaces by default [...] The server%27s /open-url endpoint handles a POST request that includes a user-input value that is passed to the unsafe open() function provided by the open NPM package, which will cause OS command execution."
0
0
0
About infosec.place
Terms of Service
This is a placeholder, overwrite this by putting a file at