CVE-2026-92784
גבוהה 7.5
תיאור (מקור, אנגלית)
@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data provider can inject malicious JavaScript through crafted JSON property names that execute in the developer's browser when the Inferencer page renders.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS 4.0
-
7.7 (HIGH)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-17/9/2026
- CWE
- CWE-94
קישורים
- https://github.com/refinedev/refine
- https://github.com/refinedev/refine/blob/main/packages/inferencer/src/create-i…
- https://github.com/refinedev/refine/blob/main/packages/inferencer/src/inferenc…
- https://github.com/refinedev/refine/issues/7556
- https://www.vulncheck.com/advisories/refinedev-inferencer-through-7.0.0-code-i…