A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/window.js of the component Open in Editor Handler. The manipulation of the argument host results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
jhen0409 react-native-debugger Open in Editor window.js openDevTools os command injection
Problem type
Affected products
jhen0409
0.1 - AFFECTED
0.2 - AFFECTED
0.3 - AFFECTED
0.4 - AFFECTED
0.5 - AFFECTED
0.6 - AFFECTED
0.7 - AFFECTED
0.8 - AFFECTED
0.9 - AFFECTED
0.10 - AFFECTED
0.11 - AFFECTED
0.12 - AFFECTED
0.13 - AFFECTED
0.14.0 - AFFECTED
References
https://vuldb.com/vuln/409351
https://vuldb.com/vuln/409351/cti
https://vuldb.com/cve/CVE-2026-97366
https://vuldb.com/submit/909329
https://gist.github.com/Suuuuuzy/d25baf1973fd3c812277e02cde2243cc
GitHub Security Advisories
GHSA-fqjr-2wgv-xw6r
A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted...
https://github.com/advisories/GHSA-fqjr-2wgv-xw6rA security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/window.js of the component Open in Editor Handler. The manipulation of the argument host results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
https://nvd.nist.gov/vuln/detail/CVE-2026-97366
https://gist.github.com/Suuuuuzy/d25baf1973fd3c812277e02cde2243cc
https://vuldb.com/cve/CVE-2026-97366
https://vuldb.com/submit/909329
https://vuldb.com/vuln/409351
https://vuldb.com/vuln/409351/cti
https://github.com/advisories/GHSA-fqjr-2wgv-xw6r
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-97366Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-97366",
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"dateUpdated": "2026-09-25T15:53:13.952Z",
"dateReserved": "2026-09-24T13:50:41.600Z",
"datePublished": "2026-09-24T20:15:10.704Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB",
"dateUpdated": "2026-09-24T20:15:10.704Z"
},
"title": "jhen0409 react-native-debugger Open in Editor window.js openDevTools os command injection",
"descriptions": [
{
"lang": "en",
"value": "A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/window.js of the component Open in Editor Handler. The manipulation of the argument host results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"affected": [
{
"vendor": "jhen0409",
"product": "react-native-debugger",
"cpes": [
"cpe:2.3:a:jhen0409:react-native-debugger:*:*:*:*:*:*:*:*"
],
"modules": [
"Open in Editor Handler"
],
"versions": [
{
"version": "0.1",
"status": "affected"
},
{
"version": "0.2",
"status": "affected"
},
{
"version": "0.3",
"status": "affected"
},
{
"version": "0.4",
"status": "affected"
},
{
"version": "0.5",
"status": "affected"
},
{
"version": "0.6",
"status": "affected"
},
{
"version": "0.7",
"status": "affected"
},
{
"version": "0.8",
"status": "affected"
},
{
"version": "0.9",
"status": "affected"
},
{
"version": "0.10",
"status": "affected"
},
{
"version": "0.11",
"status": "affected"
},
{
"version": "0.12",
"status": "affected"
},
{
"version": "0.13",
"status": "affected"
},
{
"version": "0.14.0",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "OS Command Injection",
"cweId": "CWE-78",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "Command Injection",
"cweId": "CWE-77",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://vuldb.com/vuln/409351",
"name": "VDB-409351 | jhen0409 react-native-debugger Open in Editor window.js openDevTools os command injection",
"tags": [
"vdb-entry",
"technical-description"
]
},
{
"url": "https://vuldb.com/vuln/409351/cti",
"name": "VDB-409351 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
]
},
{
"url": "https://vuldb.com/cve/CVE-2026-97366",
"name": "CVE-2026-97366 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://vuldb.com/submit/909329",
"name": "Submit #909329 | React Native Debugger v0.14.0 Improper Control of Generation of Code",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://gist.github.com/Suuuuuzy/d25baf1973fd3c812277e02cde2243cc",
"tags": [
"exploit"
]
}
],
"metrics": [
{},
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 6.3,
"baseSeverity": "MEDIUM"
}
},
{
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 6.3,
"baseSeverity": "MEDIUM"
}
},
{
"cvssV2_0": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"baseScore": 7.5
}
}
],
"timeline": [
{
"time": "2026-09-24T00:00:00.000Z",
"lang": "en",
"value": "Advisory disclosed"
},
{
"time": "2026-09-24T02:00:00.000Z",
"lang": "en",
"value": "VulDB entry created"
},
{
"time": "2026-09-24T15:55:47.000Z",
"lang": "en",
"value": "VulDB entry last update"
}
],
"credits": [
{
"lang": "en",
"value": "Jianjia Yu (VulDB User)",
"type": "reporter"
},
{
"lang": "en",
"value": "VulDB CNA Team",
"type": "coordinator"
}
]
},
"adp": [
{
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2026-09-25T15:53:13.952Z"
},
"title": "CISA ADP Vulnrichment",
"metrics": [
{}
]
}
]
}
}