Impact
@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. If an attacker controls the data provider, they can craft JSON property names that contain malicious JavaScript. When the Inferencer page renders in a developer's browser, these scripts execute, giving the attacker code‑execution capability within the page context. This bug aligns with CWE‑94, where untrusted input is processed as code, and results in a high‑severity client‑side code injection.
Affected Systems
The vulnerable component is the refine framework’s inferencer package, version 7.0.0 or earlier, distributed under the refinedev repository. Any project that includes @refinedev/inferencer and consumes data from an untrusted source is potentially affected. The estimate does not list specific downstream products, but any application built with refine that relies on inferencer and connects to an external API falls within scope.
Risk and Exploitability
The CVSS score of 7.7 categorizes the issue as high severity. The EPSS score is less than 1 %, indicating a very low current exploitation probability, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is network, where an attacker who can supply or modify the JSON returned by an API can inject dangerous field names that become part of the rendered JSX and run in any developer’s browser visiting the page. Successful exploitation would grant the attacker the ability to execute arbitrary JavaScript in the page’s context, potentially exfiltrating data or hijacking the user session.
OpenCVE Enrichment