Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Callstack

Callstack Vendor Cyber Rating & Cyber Score

callstack.com

Cross-platform engineering, built for scale ⚛️ We help businesses build and scale cross-platform apps—web, mobile, desktop, TV, and beyond—faster and with fewer trade-offs. Our services span Consulting, Product Development, and Enterprise Solutions, tailored to meet the needs of companies at every stage of growth. React Universe: one model, every platform 🌌 We use a single programming model—rooted in React and React Native—to build apps that run seamlessly across platforms. That means fewer silos, faster time to market, and tighter team collaboration. React, created by Meta and backed by a global open source community, has become the industry standard for building modern user interfaces. With React Native, that same model extends far


Callstack A.I CyberSecurity Scoring

Callstack
Company Information
Website:http://callstack.com
Employees number:206
Number of followers:8,553
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:callstack.com
Callstack Risk Score (AI oriented)
Between 700 and 749
logo
CallstackIT Services and IT Consulting
Updated:
02/04/2026
737/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Callstack Global Score (TPRM)
xxxx
logo
CallstackIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Callstack
CallstackModerate
Current Score
737Ba (MODERATE)
01000
1 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
739Before Incident
JULY 2026
739Before Incident
JUNE 2026
738Before Incident
MAY 2026
737Before Incident
APRIL 2026
737Before Incident
MARCH 2026
736Before Incident
FEBRUARY 2026
736Before Incident
JANUARY 2026
735Before Incident
DECEMBER 2025
752Before Incident
Cyber Attack
21 Dec 2025Callstack
Organizations using React Native Metro: Hackers exploit critical React Native Metro bug to breach dev systems

Hackers Exploit Critical React Native Metro Vulnerability (CVE-2025-11953) for Cross-Platform Attacks

735After Incident
CRITICAL-17
CAL1770166797
Hackers Exploit Critical React Native Metro Vulnerability (CVE-2025-11953) for Cross-Platform Attacks A critical vulnerability in the Metro server for React Native (CVE-2025-11953) is being actively exploited by threat actors to deliver malicious payloads on Windows and Linux systems. The flaw, discovered by JFrog in early November 2025, allows unauthenticated attackers to execute arbitrary OS commands via a crafted POST request to the `/open-url` endpoint, which processes unsanitized user-supplied URLs. Metro, the default JavaScript bundler for React Native, is widely used in development environments and binds to external network interfaces by default, exposing HTTP endpoints. The vulnerability affects @react-native-community/cli-server-api versions 4.8.0 through 20.0.0-alpha.2, with a patch released in version 20.0.0. Exploitation Timeline & Attack Details On December 21, 2025, vulnerability intelligence firm VulnCheck identified active exploitation of the flaw dubbed Metro4Shell with follow-up attacks observed on January 4 and 21, 2025. The threat actor delivered base-64 encoded PowerShell payloads via HTTP POST requests, targeting exposed Metro servers. Once executed, the payloads: - Disabled endpoint protections by adding Microsoft Defender exclusion paths. - Established a raw TCP connection to attacker-controlled infrastructure to fetch a second-stage payload. - Downloaded and executed a Rust-based UPX-packed binary with anti-analysis features, using an oversized argument string to evade detection. The same infrastructure hosted payloads for both Windows and Linux, confirming cross-platform targeting. Scans using ZoomEye identified approximately 3,500 exposed Metro servers online, highlighting the potential attack surface. Despite active exploitation, the vulnerability remains low-scoring in the Exploit Prediction Scoring System (EPSS), underscoring risks in relying solely on such metrics for prioritization. VulnCheck’s report includes indicators of compromise (IoCs) for the attacker’s infrastructure and payloads.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: Windows, Linux
NOVEMBER 2025
752Before Incident
OCTOBER 2025
752Before Incident
SEPTEMBER 2025
752Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Callstack ?
?
What was Callstack's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Callstack's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Callstack's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Callstack's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Callstack's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Callstack's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Callstack's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Callstack's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Callstack's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Callstack's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Callstack's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Callstack's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Callstack ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Callstack's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?