DIRAS TAKE
Act urgently: public exploit code is available, so prioritize mitigation for developer machines and CI runners using create-react-app 5.0.0–5.0.1 and apply vendor guidance or containment until a fix is released.
What is CVE-2026-14802?
An attacker can execute operating-system commands on machines running create-react-app when the vulnerable startBrowserProcess function in react-dev-utils' openBrowser.js is invoked; this is tracked as CVE-2026-14802. The bug affects create-react-app versions 5.0.0 and 5.0.1 (reported on macOS). The CVSS vector indicates no privileges or user interaction are required, and the vulnerability can be triggered remotely in exposed environments. The weakness is classified as CWE-78 (OS Command Injection).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Which versions of react create-react-app are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 5.x | 5.0.0 | |
| 5.x | 5.0.1 |
Is CVE-2026-14802 being exploited?
Public exploit code is available.
How to fix CVE-2026-14802
- Isolate or block external access to development servers and developer tooling that run create-react-app on macOS.
- Remove or disable use of the react-dev-utils openBrowser/startBrowserProcess component where feasible (for example, start the dev server without opening a browser).
- Monitor developer and CI hosts for unexpected process executions and suspicious command activity related to browser-launching utilities.
- Apply the vendor's guidance and deploy an official fix as soon as a patched react-dev-utils or create-react-app release is published.
Frequently asked questions
Is CVE-2026-14802 being actively exploited?
Public exploit code is available for CVE-2026-14802, which increases the risk of active exploitation.
Which create-react-app versions are affected by CVE-2026-14802?
create-react-app versions 5.0.0 and 5.0.1 are listed as affected by CVE-2026-14802 (issue reported on macOS).
Is there a patch for CVE-2026-14802?
No patch was listed as available as of 2026-09-29; follow vendor guidance and apply mitigations until an official fix is released.
Does CVE-2026-14802 require authentication?
No; the vulnerability does not require privileges or user interaction according to the reported CVSS vector, so it can be triggered without authentication or a user click.
References
- nvd.nist.gov/vuln/detail/CVE-2026-14802
- cve.org/CVERecord?id=CVE-2026-14802
- vuldb.com/vuln/376396
- vuldb.com/vuln/376396/cti
- vuldb.com/cve/CVE-2026-14802
- vuldb.com/submit/850857
- github.com/react/create-react-app/issues/17269
- github.com/react/create-react-app
- All react CVEs on CVE Radar
- CVEs published in September 2026