AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-14802.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 5.5CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 01, 2026

Disclosure summary

A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-g9g6-gvq9-j4vp

Open original source · Updated Oct 01, 2026

react-dev-utils openBrowser permits command injection on macOS

Source severity: MEDIUM / 5.5

EcosystemPackageAffected rangeFirst patched
npmreact-dev-utilsNot supplied

Original records & references

PUBLISHED 2026-07-06T05:30:27-04:00
MODIFIED 2026-10-01T17:08:57-04:00
INGESTED 2026-10-06T11:45:17-04:00