CRITICAL
dai-shi
CVE published 2026-08-10
CVE-2026-48159
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T18:17:49.547Z and has not been modified since then. The use-reducer-async package, a React useReducer with async actions, was compromised between 2026-05-18 16:29:52 and 2026-05-19 15:26:07. Malicious commits were added to the default branch, which executed remote attacker-controlled code on deve [truncated]