CVE-2026-14802
published 2026-07-06CVE-2026-14802: A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file openBrowser.js of the…
PriorityP357high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
2.11%
81.2th percentile
A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| react-dev-utils | 0 – 5.0.1 | — | |
| react | create-react-app | — | — |
| react | create-react-app | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
react-dev-utils openBrowser permits command injection on macOS
ghsa·2026-07-06
CVE-2026-14802 [MEDIUM] CWE-77 react-dev-utils openBrowser permits command injection on macOS
react-dev-utils openBrowser permits command injection on macOS
A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
GHSA
A vulnerability was detected in react create-react-app up to 5.0.1 on macOS.
ghsa_unreviewed·2026-07-06
CVE-2026-14802 [MEDIUM] CWE-77 A vulnerability was detected in react create-react-app up to 5.0.1 on macOS.
A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
VulDB
react create-react-app up to 5.0.1 on macOS react-dev-utils openBrowser.js startBrowserProcess os command injection (Issue 17269)
vuldb·2026-07-05
CVE-2026-14802 [CRITICAL] react create-react-app up to 5.0.1 on macOS react-dev-utils openBrowser.js startBrowserProcess os command injection (Issue 17269)
A vulnerability was found in react create-react-app up to 5.0.1 on macOS. It has been classified as critical. This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. Performing a manipulation results in os command injection.
This vulnerability is known as CVE-2026-14802. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-06
Published