---
id: CVE-2026-92784
title: >-
  @refinedev/inferencer through 7.0.0 fails to escape API field names when
  interpolating them into generated JSX source code
summary: >-
  @refinedev/inferencer through 7.0.0 fails to escape API field names when
  interpolating them into generated JSX source code. Attackers controlling the
  data provider can inject malicious JavaScript through crafted JSON property
  names that …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: refinedev
product: '@refinedev/inferencer'
affected:
  - '@refinedev/inferencer <= 7.0.0'
published: '2026-09-16'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:55.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92784'
references:
  - url: 'https://github.com/refinedev/refine'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/refinedev/refine/blob/main/packages/inferencer/src/create-inferencer/index.tsx#L117-L128
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/refinedev/refine/blob/main/packages/inferencer/src/inferencers/antd/list.tsx#L140-L144
    label: disclosure@vulncheck.com
  - url: 'https://github.com/refinedev/refine/issues/7556'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/refinedev-inferencer-through-7.0.0-code-injection-via-api-field-names
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00477
epssPercentile: 0.38721
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T18:57:19.869133Z'
ingestedAt: '2026-09-16T21:05:36.889Z'
---

## Overview

@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data provider can inject malicious JavaScript through crafted JSON property names that execute in the developer's browser when the Inferencer page renders.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
