CVE-2026-14802

Source
https://cve.org/CVERecord?id=CVE-2026-14802
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14802.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-14802
Published
2026-07-06T06:30:08.952Z
Modified
2026-07-15T01:48:57.325919643Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
react create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injection
Details

A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cwe_ids": [
        "CWE-77",
        "CWE-78"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14802.json",
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/react/create-react-app

Affected ranges

Type
GIT
Repo
https://github.com/react/create-react-app
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "5.0.0"
        },
        {
            "last_affected": "5.0.0"
        },
        {
            "introduced": "5.0.1"
        },
        {
            "last_affected": "5.0.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

5.*
5.0.0
5.0.1
cra-template-typescript@1.*
cra-template-typescript@1.2.0
cra-template@1.*
cra-template@1.2.0
create-react-app@5.*
create-react-app@5.0.1
eslint-config-react-app@7.*
eslint-config-react-app@7.0.1
react-dev-utils@12.*
react-dev-utils@12.0.1
react-error-overlay@6.*
react-error-overlay@6.0.11
react-scripts@5.*
react-scripts@5.0.1
v5.*
v5.0.0
v5.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14802.json"