Code Injection Vulnerability in Inferencer by RefineDev
CVE-2026-92784

7.7HIGH

Key Information:

Vendor

Refinedev

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92784?

The Inferencer product by RefineDev, up to version 7.0.0, is susceptible to a code injection vulnerability. This arises from the failure to escape API field names during JSX source code generation. Attackers who control the data provider can take advantage of this flaw by injecting malicious JavaScript through specially crafted JSON property names. When the Inferencer page is rendered, the injected script executes in the browser of the developer, posing significant security risks.

Affected Version(s)

@refinedev/inferencer 0 <= 7.0.0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.