Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x4x4-phr8-wp7p

Опубликовано: 16 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.7
CVSS3: 7.5

Описание

@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data provider can inject malicious JavaScript through crafted JSON property names that execute in the developer's browser when the Inferencer page renders.

@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data provider can inject malicious JavaScript through crafted JSON property names that execute in the developer's browser when the Inferencer page renders.

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.5
nvd
1 день назад

@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data provider can inject malicious JavaScript through crafted JSON property names that execute in the developer's browser when the Inferencer page renders.

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-94