CVE-2026-92784: Refinedev @refinedev/inferencer

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data provider can inject malicious JavaScript through crafted JSON property names that execute in the developer's browser when the Inferencer page renders.

Affected products

  • Refinedev @refinedev/inferencer: up to and including 7.0.0

Published 2026-09-16. Last modified 2026-09-24.