🛡️ CVE-2026-45321
🔴 CVSS 9.6 — Critical ✅ No Known Exploit CWE-506 NVD
9.6
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.

Details

Severity CRITICAL
CVSS Score 9.6
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CWE CWE-506
Public Exploit ✅ No
Source NVD
Published 2026-05-12
Updated 2026-06-09
Modified 2026-06-09
Fix URL N/A

Affected Packages

Software From version Fixed in
@tanstack/arktype-adapter
@tanstack/eslint-plugin-router
@tanstack/eslint-plugin-start
@tanstack/history
@tanstack/nitro-v2-vite-plugin
@tanstack/react-router
@tanstack/react-router-devtools
@tanstack/react-router-ssr-query
@tanstack/react-start
@tanstack/react-start-client
@tanstack/react-start-rsc
@tanstack/react-start-server
@tanstack/router-cli
@tanstack/router-core
@tanstack/router-devtools
@tanstack/router-devtools-core
@tanstack/router-generator
@tanstack/router-plugin
@tanstack/router-ssr-query-core
@tanstack/router-utils
@tanstack/router-vite-plugin
@tanstack/solid-router
@tanstack/solid-router-devtools
@tanstack/solid-router-ssr-query
@tanstack/solid-start
@tanstack/solid-start-client
@tanstack/solid-start-server
@tanstack/start-client-core
@tanstack/start-fn-stubs
@tanstack/start-plugin-core
@tanstack/start-server-core
@tanstack/start-static-server-functions
@tanstack/start-storage-context
@tanstack/valibot-adapter
@tanstack/virtual-file-routes
@tanstack/vue-router
@tanstack/vue-router-devtools
@tanstack/vue-router-ssr-query
@tanstack/vue-start
@tanstack/vue-start-client
@tanstack/vue-start-server
@tanstack/zod-adapter
agentwork-cli
beproduct\/nestjs-auth
cmux-agent-mcp
cross-stitch
dirigible-ai\/sdk
draftauth\/client
draftauth\/core
draftlab\/auth
draftlab\/auth-router
draftlab\/db
git-branch-selector
git-git-git
guardrails-ai
mesadev\/rest
mesadev\/saguaro
mesadev\/sdk
mistralai
mistralai\/mistralai
mistralai\/mistralai-azure
mistralai\/mistralai-gcp
ml-toolkit-ts
ml-toolkit-ts\/preprocessing
ml-toolkit-ts\/xgboost
nextmove-mcp
opensearch
simple-type-safe-actions
squawk\/airports
squawk\/airspace
squawk\/airspace-data
squawk\/airway-data
squawk\/airways
squawk\/fix-data
squawk\/fixes
squawk\/flight-math
squawk\/flightplan
squawk\/geo
squawk\/icao-registry
squawk\/icao-registry-data
squawk\/mcp
squawk\/navaid-data
squawk\/navaids
squawk\/notams
squawk\/procedure-data
squawk\/procedures
squawk\/types
squawk\/units
squawk\/weather
supersurkhet\/cli
supersurkhet\/sdk
tallyui\/components
tallyui\/connector-medusa
tallyui\/connector-shopify
tallyui\/connector-vendure
tallyui\/connector-woocommerce
tallyui\/core
tallyui\/database
tallyui\/pos
tallyui\/storage-sqlite
tallyui\/theme
tanstack\/arktype-adapter
tanstack\/eslint-plugin-router
tanstack\/eslint-plugin-start
tanstack\/history
tanstack\/nitro-v2-vite-plugin
tanstack\/react-router
tanstack\/react-router-devtools
tanstack\/react-router-ssr-query
tanstack\/react-start
tanstack\/react-start-client
tanstack\/react-start-rsc
tanstack\/react-start-server
tanstack\/router-cli
tanstack\/router-core
tanstack\/router-devtools
tanstack\/router-devtools-core
tanstack\/router-generator
tanstack\/router-plugin
tanstack\/router-ssr-query-core
tanstack\/router-utils
tanstack\/router-vite-plugin
tanstack\/solid-router
tanstack\/solid-router-devtools
tanstack\/solid-router-ssr-query
tanstack\/solid-start
tanstack\/solid-start-client
tanstack\/solid-start-server
tanstack\/start-client-core
tanstack\/start-fn-stubs
tanstack\/start-plugin-core
tanstack\/start-server-core
tanstack\/start-static-server-functions
tanstack\/start-storage-context
tanstack\/valibot-adapter
tanstack\/virtual-file-routes
tanstack\/vue-router
tanstack\/vue-router-devtools
tanstack\/vue-router-ssr-query
tanstack\/vue-start
tanstack\/vue-start-client
tanstack\/vue-start-server
tanstack\/zod-adapter
taskflow-corp\/cli
tolka\/cli
ts-dna
uipath\/access-policy-sdk
uipath\/access-policy-tool
uipath\/admin-tool
uipath\/agent-sdk
uipath\/agent-tool
uipath\/agent.sdk
uipath\/aops-policy-tool
uipath\/ap-chat
uipath\/api-workflow-tool
uipath\/apollo-core
uipath\/apollo-react
uipath\/apollo-wind
uipath\/auth
uipath\/case-tool
uipath\/cli
uipath\/codedagent-tool
uipath\/codedagents-tool
uipath\/codedapp-tool
uipath\/common
uipath\/context-grounding-tool
uipath\/data-fabric-tool
uipath\/docsai-tool
uipath\/filesystem
uipath\/flow-tool
uipath\/functions-tool
uipath\/gov-tool
uipath\/identity-tool
uipath\/insights-sdk
uipath\/insights-tool
uipath\/integrationservice-sdk
uipath\/integrationservice-tool
uipath\/llmgw-tool
uipath\/maestro-sdk
uipath\/maestro-tool
uipath\/orchestrator-tool
uipath\/packager-tool-apiworkflow
uipath\/packager-tool-bpmn
uipath\/packager-tool-case
uipath\/packager-tool-connector
uipath\/packager-tool-flow
uipath\/packager-tool-functions
uipath\/packager-tool-webapp
uipath\/packager-tool-workflowcompiler
uipath\/packager-tool-workflowcompiler-browser
uipath\/platform-tool
uipath\/project-packager
uipath\/resource-tool
uipath\/resourcecatalog-tool
uipath\/resources-tool
uipath\/robot
uipath\/rpa-legacy-tool
uipath\/rpa-tool
uipath\/solution-packager
uipath\/solution-tool
uipath\/solutionpackager-sdk
uipath\/solutionpackager-tool-core
uipath\/tasks-tool
uipath\/telemetry
uipath\/test-manager-tool
uipath\/tool-workflowcompiler
uipath\/traces-tool
uipath\/ui-widgets-multi-file-upload
uipath\/uipath-python-bridge
uipath\/vertical-solutions-tool
uipath\/vss
uipath\/widget.sdk
unknown
wot-api

Similar Threats

Site Security Check

Concerned your site may already be targeted?

BotEraser analyzes incoming traffic patterns and helps identify bot behavior consistent with known exploit attempts.

Check My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.