← Back to browse · API

CVE-2026-45321

Severity
CRITICAL
CVSS
9.6
EPSS
0.02342
Risk score
64.22
CISA KEV
Yes
PoC
No
Published
2026-05-12
Modified
2026-08-04
First seen
2026-08-07
Aliases
EUVD-2026-29352, GHSA-G7CV-RXG3-HMPX
Products
@tanstack:arktype-adapter 1.166.12, @tanstack:arktype-adapter 1.166.15, @tanstack:eslint-plugin-router 1.161.9, @tanstack:eslint-plugin-start 0.0.4, @tanstack:eslint-plugin-start 0.0.7, @tanstack:history 1.161.12, @tanstack:history 1.161.9, @tanstack:nitro-v2-vite-plugin 1.154.15, @tanstack:outer-vite-plugin 1.166.53, @tanstack:outer-vite-plugin 1.166.56, @tanstack:react-router 1.169.5, @tanstack:react-router 1.169.8, @tanstack:react-router-ssr-query 1.166.15, @tanstack:react-router-ssr-query 1.166.18, @tanstack:react-start 1.167.71, @tanstack:react-start-client 1.166.51, @tanstack:react-start-rsc 0.0.47, @tanstack:react-start-rsc 0.0.50, @tanstack:router-core 1.169.8, @tanstack:router-devtools 1.166.16, @tanstack:router-devtools 1.166.19, @tanstack:router-devtools-core 1.167.9, @tanstack:router-generator 1.166.45, @tanstack:router-generator 1.166.48, @tanstack:router-plugin 1.167.38, @tanstack:router-utils 1.161.14, @tanstack:solid-router 1.169.5, @tanstack:solid-router 1.169.8, @tanstack:solid-router-ssr-query 1.166.15, @tanstack:solid-router-ssr-query 1.166.18, @tanstack:solid-start-client 1.166.50, @tanstack:solid-start-server 1.166.54, @tanstack:start-client-core 1.168.5, @tanstack:start-fn-stubs 1.161.9, @tanstack:start-plugin-core 1.169.23, @tanstack:start-server-core 1.167.33, @tanstack:start-static-server-functions 1.166.44, @tanstack:start-static-server-functions 1.166.47, @tanstack:start-storage-context 1.166.41, @tanstack:valibot-adapter 1.166.15, @tanstack:virtual-file-routes 1.161.13, @tanstack:vue-router 1.169.5, @tanstack:vue-router 1.169.8, @tanstack:vue-router-devtools 1.166.16, @tanstack:vue-router-devtools 1.166.19, @tanstack:vue-router-ssr-query 1.166.15, @tanstack:vue-start-client 1.166.46, @tanstack:vue-start-server 1.166.50, @tanstack:vue-start-server 1.166.53, @tanstack:zod-adapter 1.166.12, TanStack:TanStack
Sources
cisa.gov CVE-2026-45321
euvd EUVD-2026-29352

Description

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.

References