A vulnerability, which was classified as critical, was found in dai-shi react18-use. Impacted is an unknown function of the file src/install.js of the component Postinstall Script. The manipulation results in permission issues.
This vulnerability is reported as CVE-2026-48161. The attack can be launched remotely. No exploit exists.
It is best practice to apply a patch to resolve this issue.