# CVE-2026-45321

## Summary

- **CVE ID:** CVE-2026-45321
- **Severity:** CRITICAL
- **CVSS Score:** 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
- **CWE:** CWE-506
- **Published:** May 12, 2026
- **Last Modified:** Aug 4, 2026

## Description

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.

## Affected Products

- @tanstack — arktype-adapter (1.166.12)
- @tanstack — arktype-adapter (1.166.15)
- @tanstack — eslint-plugin-router (1.161.9)
- @tanstack — eslint-plugin-router (1.161.12)
- @tanstack — eslint-plugin-start (0.0.4)
- @tanstack — eslint-plugin-start (0.0.7)
- @tanstack — history (1.161.9)
- @tanstack — history (1.161.12)
- @tanstack — nitro-v2-vite-plugin (1.154.12)
- @tanstack — nitro-v2-vite-plugin (1.154.15)
- @tanstack — react-router (1.169.5)
- @tanstack — react-router (1.169.8)
- @tanstack — react-router-devtools (1.166.16)
- @tanstack — react-router-devtools (1.166.19)
- @tanstack — react-router-ssr-query (1.166.15)
- @tanstack — react-router-ssr-query (1.166.18)
- @tanstack — react-start (1.167.68)
- @tanstack — react-start (1.167.71)
- @tanstack — react-start-client (1.166.51)
- @tanstack — react-start-client (1.166.54)
- @tanstack — react-start-rsc (0.0.47)
- @tanstack — react-start-rsc (0.0.50)
- @tanstack — react-start-server (1.166.55)
- @tanstack — react-start-server (1.166.58)
- @tanstack — router-cli (1.166.46)
- @tanstack — router-cli (1.166.49)
- @tanstack — router-core (1.169.5)
- @tanstack — router-core (1.169.8)
- @tanstack — router-devtools (1.166.16)
- @tanstack — router-devtools (1.166.19)
- @tanstack — router-devtools-core (1.167.6)
- @tanstack — router-devtools-core (1.167.9)
- @tanstack — router-generator (1.166.45)
- @tanstack — router-generator (1.166.48)
- @tanstack — router-plugin (1.167.38)
- @tanstack — router-plugin (1.167.41)
- @tanstack — router-ssr-query-core (1.168.3)
- @tanstack — router-ssr-query-core (1.168.6)
- @tanstack — router-utils (1.161.11)
- @tanstack — router-utils (1.161.14)
- @tanstack — outer-vite-plugin (1.166.53)
- @tanstack — outer-vite-plugin (1.166.56)
- @tanstack — solid-router (1.169.5)
- @tanstack — solid-router (1.169.8)
- @tanstack — solid-router-devtools (1.166.16)
- @tanstack — solid-router-devtools (1.166.19)
- @tanstack — solid-router-ssr-query (1.166.15)
- @tanstack — solid-router-ssr-query (1.166.18)
- @tanstack — solid-start (1.167.65)
- @tanstack — solid-start (1.167.68)
- @tanstack — solid-start-client (1.166.50)
- @tanstack — solid-start-client (1.166.53)
- @tanstack — solid-start-server (1.166.54)
- @tanstack — solid-start-server (1.166.57)
- @tanstack — start-client-core (1.168.5)
- @tanstack — start-client-core (1.168.8)
- @tanstack — start-fn-stubs (1.161.9)
- @tanstack — start-fn-stubs (1.161.12)
- @tanstack — start-plugin-core (1.169.23)
- @tanstack — start-plugin-core (1.169.26)
- @tanstack — start-server-core (1.167.33)
- @tanstack — start-server-core (1.167.36)
- @tanstack — start-static-server-functions (1.166.44)
- @tanstack — start-static-server-functions (1.166.47)
- @tanstack — start-storage-context (1.166.38)
- @tanstack — start-storage-context (1.166.41)
- @tanstack — valibot-adapter (1.166.12)
- @tanstack — valibot-adapter (1.166.15)
- @tanstack — virtual-file-routes (1.161.10)
- @tanstack — virtual-file-routes (1.161.13)
- @tanstack — vue-router (1.169.5)
- @tanstack — vue-router (1.169.8)
- @tanstack — vue-router-devtools (1.166.16)
- @tanstack — vue-router-devtools (1.166.19)
- @tanstack — vue-router-ssr-query (1.166.15)
- @tanstack — vue-router-ssr-query (1.166.18)
- @tanstack — vue-start (1.167.61)
- @tanstack — vue-start (1.167.64)
- @tanstack — vue-start-client (1.166.46)
- @tanstack — vue-start-client (1.166.49)
- @tanstack — vue-start-server (1.166.50)
- @tanstack — vue-start-server (1.166.53)
- @tanstack — zod-adapter (1.166.12)
- @tanstack — zod-adapter (1.166.15)

## References

- [CNA](https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx)
- [CNA](https://github.com/TanStack/router/issues/7383)
- [CNA](https://tanstack.com/blog/npm-supply-chain-compromise-postmortem)
- [CNA](https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45321)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 2.34%
- **EPSS Percentile:** 82.6

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** May 27, 2026
- **Due Date:** Jun 10, 2026

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._