TanStack Unspecified Vulnerability
High Listed in CISA KEV
Summary
TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- TanStack:TanStack
Sources
- CISA KEV DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2026-45321 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx reference
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV