A vulnerability was found in TanStack devtools-vite 0.7.0. Affected by this issue is the function installPackage of the file packages/devtools-bundler-core/src/package-manager.ts of the component Dev…
Medium CVSS 4.5
Summary
A vulnerability was found in TanStack devtools-vite 0.7.0. Affected by this issue is the function installPackage of the file packages/devtools-bundler-core/src/package-manager.ts of the component Development Devtools Event Bus. The manipulation of the argument packageName results in os command injection. Attacking locally is a requirement. A high complexity level is associated with this attack. The exploitation is known to be difficult. The exploit has been made public and could be used. The pr…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/TanStack/devtools/issues/464
- https://vuldb.com/cve/CVE-2026-78177
- https://vuldb.com/submit/884155
- https://vuldb.com/vuln/394561
- https://vuldb.com/vuln/394561/cti
Timeline
- nvd_ingest NVD