HIGH

CVE-2026-92784

2026-09-16 CVSS v3.1
CVSS
7.5

Description

@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data provider can inject malicious JavaScript through crafted JSON property names that execute in the developer's browser when the Inferencer page renders.

Weakness (CWE)

CWE-94 Code Injection

EPSS Score

0.44%
Probability of exploitation in next 30 days
37.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE