A vulnerability has been found in dai-shi react-tracked and classified as critical. Affected by this vulnerability is an unknown functionality of the file src/install.js of the component Postinstall Script. Performing a manipulation results in code injection.

This vulnerability is known as CVE-2026-48160. Remote exploitation of the attack is possible. No exploit is available.

To fix this issue, it is recommended to deploy a patch.