A vulnerability labeled as critical has been found in dai-shi use-reducer-async. Affected by this vulnerability is an unknown functionality of the file src/install.js of the component Postinstall Script. Executing a manipulation can lead to code injection.
This vulnerability appears as CVE-2026-48159. The attack may be performed from remote. There is no available exploit.
It is best practice to apply a patch to resolve this issue.