HIGH
CVE-2026-92784
CVSS
7.5
Description
@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data provider can inject malicious JavaScript through crafted JSON property names that execute in the developer's browser when the Inferencer page renders.
Weakness (CWE)
CWE-94
Code Injection
EPSS Score
0.44%
Probability of exploitation in next 30 days
37.5th percentile
References
https://github.com/refinedev/refine
https://github.com/refinedev/refine/blob/main/packages/inferencer/src/create-inferencer/index.tsx#L117-L128
https://github.com/refinedev/refine/blob/main/packages/inferencer/src/inferencers/antd/list.tsx#L140-L144
https://github.com/refinedev/refine/issues/7556
https://www.vulncheck.com/advisories/refinedev-inferencer-through-7.0.0-code-injection-via-api-field-names
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.