peter bassill · operator
$ cve CVE-2026-45321 JSON

CVE-2026-45321 KEV

9.6
CRITICAL · CVSS 3.1 · EPSS 1.1% (pctl 63)

Patch first

On CISA KEV — known exploited in the wild, due 2026-06-10.

Description

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.

Scoring

CVSS9.6 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS1.05% — more likely to be exploited than 63% of all CVEs
WeaknessCWE-506
On CISA KEVyes — remediate by 2026-06-10
Public exploitnone known
Published2026-05-12
Last modified2026-06-17

CISA KEV

NameTanStack Unspecified Vulnerability
Added2026-05-27
Due2026-06-10
Vendor / productTanStack / TanStack
Ransomware useknown

Affected (40)

VendorProduct
tanstacktanstack\/arktype-adapter
tanstacktanstack\/eslint-plugin-router
tanstacktanstack\/eslint-plugin-start
tanstacktanstack\/history
tanstacktanstack\/nitro-v2-vite-plugin
tanstacktanstack\/react-router
tanstacktanstack\/react-router-devtools
tanstacktanstack\/react-router-ssr-query
tanstacktanstack\/react-start
tanstacktanstack\/react-start-client
tanstacktanstack\/react-start-rsc
tanstacktanstack\/react-start-server
tanstacktanstack\/router-cli
tanstacktanstack\/router-core
tanstacktanstack\/router-devtools
tanstacktanstack\/router-devtools-core
tanstacktanstack\/router-generator
tanstacktanstack\/router-plugin
tanstacktanstack\/router-ssr-query-core
tanstacktanstack\/router-utils
tanstacktanstack\/router-vite-plugin
tanstacktanstack\/solid-router
tanstacktanstack\/solid-router-devtools
tanstacktanstack\/solid-router-ssr-query
tanstacktanstack\/solid-start
tanstacktanstack\/solid-start-client
tanstacktanstack\/solid-start-server
tanstacktanstack\/start-client-core
tanstacktanstack\/start-fn-stubs
tanstacktanstack\/start-plugin-core
tanstacktanstack\/start-server-core
tanstacktanstack\/start-static-server-functions
tanstacktanstack\/start-storage-context
tanstacktanstack\/valibot-adapter
tanstacktanstack\/virtual-file-routes
tanstacktanstack\/vue-router
tanstacktanstack\/vue-router-devtools
tanstacktanstack\/vue-router-ssr-query
tanstacktanstack\/vue-start
tanstacktanstack\/vue-start-client

References

→ the Explorer  ·  watch your stack  ·  NVD