A widely popular npm package carried a critical severity vulnerability that allowed threat actors to, in certain scenarios, run malicious commands, experts have warned.
The bug exposes the Metro development server to remote attacks, allowing arbitrary OS command execution on developer systems ...