{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/refine/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:refine:inferencer:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-92784"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["inferencer (\u003c= 7.0.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Refine"],"content_html":"\u003cp\u003eThe @refinedev/inferencer package, used for automating the generation of views and forms based on API data structures, contains a critical security flaw (CVE-2026-92784) in versions through 7.0.0. The vulnerability stems from improper neutralization of input data when the package interpolates API field names into generated JSX source code.\u003c/p\u003e\n\u003cp\u003eAn attacker capable of influencing the data returned by the application's data provider can inject malicious JavaScript payloads within JSON property names. When a developer utilizes the Inferencer feature to render a page based on this data, the payload is injected directly into the component source code. This results in Cross-Site Scripting (XSS) executing in the context of the developer's browser environment. This vulnerability is significant for development environments where Inferencer is used to parse untrusted or externally sourced API responses, potentially leading to unauthorized data access or session hijacking within the development environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the execution of arbitrary JavaScript within the developer's browser when they interact with the Inferencer-generated interface. This can lead to the compromise of local development session tokens, exfiltration of local sensitive data, or unauthorized actions performed on behalf of the developer. As the tool is often used to parse API schemas during development, this impacts software supply chain security and the integrity of the local development environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the update of the @refinedev/inferencer package to a version that addresses CVE-2026-92784. If an immediate update is not feasible, restrict the use of the Inferencer component to data providers that are trusted and verified, ensuring that JSON property names in API responses do not contain arbitrary or user-controllable input.\u003c/p\u003e\n","date_modified":"2026-09-16T21:56:34Z","date_published":"2026-09-16T21:56:34Z","id":"https://feed.craftedsignal.io/briefs/2026-09-refinedev-inferencer-xss/","summary":"The @refinedev/inferencer package versions through 7.0.0 are vulnerable to an injection attack where malicious JSON property names are improperly escaped during JSX code generation, leading to arbitrary JavaScript execution in the developer's browser.","title":"Cross-Site Scripting via @refinedev/inferencer","url":"https://feed.craftedsignal.io/briefs/2026-09-refinedev-inferencer-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Refine","version":"https://jsonfeed.org/version/1.1"}