A vulnerability labeled as critical has been found in dai-shi use-reducer-async. Affected by this vulnerability is an unknown functionality of the file src/install.js of the component Postinstall Script. Executing a manipulation can lead to code injection.

This vulnerability appears as CVE-2026-48159. The attack may be performed from remote. There is no available exploit.

It is best practice to apply a patch to resolve this issue.