CVE-2026-92784 PUBLISHED

@refinedev/inferencer through 7.0.0 Code Injection via API Field Names

Assigner: VulnCheck
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data provider can inject malicious JavaScript through crafted JSON property names that execute in the developer's browser when the Inferencer page renders.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.7

Product Status

Vendor refinedev
Product @refinedev/inferencer
Versions Default: unaffected
  • affected from 0 to 7.0.0 (incl.)

Credits

  • George Chen finder

References

Problem Types

  • Improper Control of Generation of Code ('Code Injection') CWE