Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
JFrog

JFrog Vendor Cyber Rating & Cyber Score

jfrog.com

Deliver Trusted Software with Speed. The only software supply chain platform to give you end-to-end visibility, security, and control for automating the delivery of trusted releases. The massively scalable, hybrid JFrog Platform is open, flexible, and integrated with all the package technologies and tools comprising the software supply chain. Organizations benefit from full traceability to any type of release and deployment environment including ML models, software that runs on the edge, and software deployed in production data centers.


JFrog A.I CyberSecurity Scoring

JFrog
Company Information
Website:https://jfrog.com/
Employees number:2,293
Number of followers:84,604
NAICS:5112
Industry Type:Software Development
Homepage:jfrog.com
JFrog Risk Score (AI oriented)
Between 750 and 799
logo
JFrogSoftware Development
Updated:
10/03/2026
768/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
JFrog Global Score (TPRM)
xxxx
logo
JFrogSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

JFrog
JFrogFair
Current Score
768Baa (FAIR)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
779Before Incident
MAY 2026
778Before Incident
APRIL 2026
778Before Incident
MARCH 2026
768Before Incident
FEBRUARY 2026
772Before Incident
JANUARY 2026
772Before Incident
DECEMBER 2025
769Before Incident
Vulnerability
21 Dec 2025JFrog
JFrog, VulnCheck and React Native: Hackers exploit critical React Native Metro bug to breach dev systems

Hackers Exploit Critical React Native Metro Vulnerability (CVE-2025-11953) for Cross-Platform Attacks

767After Incident
LOW-2
VULJFRREA1770209168
Hackers Exploit Critical React Native Metro Vulnerability (CVE-2025-11953) for Cross-Platform Attacks Hackers are actively exploiting CVE-2025-11953, a critical vulnerability in the Metro server for React Native, to deliver malicious payloads targeting Windows and Linux systems. The flaw, discovered by JFrog in early November 2025, allows unauthenticated attackers to execute arbitrary OS commands via a crafted POST request to the `/open-url` endpoint. Metro, the default JavaScript bundler for React Native, is widely used in development environments. The vulnerability stems from unsanitized user-supplied URLs passed to the `open()` function, affecting @react-native-community/cli-server-api versions 4.8.0 through 20.0.0-alpha.2. A patch was released in version 20.0.0. Exploitation Timeline & Impact VulnCheck first observed attacks on December 21, 2025, with follow-up activity on January 4 and 21, 2025. Dubbed Metro4Shell, the campaign delivers base-64 encoded PowerShell payloads that: - Disable Microsoft Defender protections by adding exclusion paths. - Establish a raw TCP connection to attacker-controlled infrastructure. - Download and execute a Rust-based UPX-packed binary with anti-analysis features. The same infrastructure hosts payloads for both Windows and Linux, confirming cross-platform targeting. Scans via ZoomEye identified ~3,500 exposed Metro servers online. Despite active exploitation, the vulnerability remains low-scoring in the Exploit Prediction Scoring System (EPSS), highlighting a gap in risk prioritization. VulnCheck’s report includes indicators of compromise (IoCs) for the attacker’s infrastructure and payloads.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: Windows, Linux
NOVEMBER 2025
769Before Incident
OCTOBER 2025
769Before Incident
SEPTEMBER 2025
769Before Incident
AUGUST 2025
769Before Incident
JULY 2025
769Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for JFrog ?
?
What was JFrog's A.I Rankiteo Cyber Score in May 2026 ?
?
What was JFrog's A.I Rankiteo Cyber Score in April 2026 ?
?
What was JFrog's A.I Rankiteo Cyber Score in March 2026 ?
?
What was JFrog's A.I Rankiteo Cyber Score in February 2026 ?
?
What was JFrog's A.I Rankiteo Cyber Score in January 2026 ?
?
What was JFrog's A.I Rankiteo Cyber Score in December 2025 ?
?
What was JFrog's A.I Rankiteo Cyber Score in November 2025 ?
?
What was JFrog's A.I Rankiteo Cyber Score in October 2025 ?
?
What was JFrog's A.I Rankiteo Cyber Score in September 2025 ?
?
What was JFrog's A.I Rankiteo Cyber Score in August 2025 ?
?
What was JFrog's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on JFrog's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with JFrog ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view JFrog's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?