Embedded malicious code in TanStack products - CVE-2026-45321
Published: May 29, 2026 / Updated: July 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and execute malicious code in the install environment.
The vulnerability exists due to presence of malicious code in compromised applications in the vendor's repository. The incident occurred on May 11, 2026 between approximately 19:20 and 19:26 UTC. Attackers have published 84 malicious versions across 42 @tanstack/* packages to the npm registry.
The malicious payload runs during npm, pnpm, or yarn installation, harvests cloud credentials, GitHub tokens, npm tokens, Kubernetes service-account tokens, Vault tokens, and SSH private keys, and exfiltrates the collected data over the Session/Oxen file-upload network.
Affected software
react-start-rsc
nitro-v2-vite-plugin
start-fn-stubs
eslint-plugin-router
history
virtual-file-routes
router-utils
arktype-adapter
valibot-adapter
zod-adapter
solid-router-ssr-query
vue-router-ssr-query
react-router-ssr-query
vue-router-devtools
solid-router-devtools
react-router-devtools
router-devtools
start-storage-context
start-static-server-functions
router-generator
router-cli
vue-start-client
vue-start-server
solid-start-client
react-start-client
router-vite-plugin
solid-start-server
react-start-server
router-devtools-core
start-server-core
router-plugin
vue-start
solid-start
react-start
router-ssr-query-core
start-client-core
vue-router
solid-router
router-core
react-router
start-plugin-core
How to mitigate CVE-2026-45321
react-start-rsc - update to 0.0.51
nitro-v2-vite-plugin - update to 1.154.16
start-fn-stubs - update to 1.161.13
eslint-plugin-router - update to 1.161.13
history - update to 1.161.13
virtual-file-routes - update to 1.161.14
router-utils - update to 1.161.15
arktype-adapter - update to 1.166.16
valibot-adapter - update to 1.166.16
zod-adapter - update to 1.166.16
solid-router-ssr-query - update to 1.166.19
vue-router-ssr-query - update to 1.166.19
react-router-ssr-query - update to 1.166.19
vue-router-devtools - update to 1.166.20
solid-router-devtools - update to 1.166.20
react-router-devtools - update to 1.166.20
router-devtools - update to 1.166.20
start-storage-context - update to 1.166.42
start-static-server-functions - update to 1.166.48
router-generator - update to 1.166.49
router-cli - update to 1.166.50
vue-start-client - update to 1.166.50
vue-start-server - update to 1.166.54
solid-start-client - update to 1.166.54
react-start-client - update to 1.166.55
router-vite-plugin - update to 1.166.57
solid-start-server - update to 1.166.58
react-start-server - update to 1.166.59
router-devtools-core - update to 1.167.10
start-server-core - update to 1.167.37
router-plugin - update to 1.167.42
vue-start - update to 1.167.65
solid-start - update to 1.167.69
react-start - update to 1.167.72
router-ssr-query-core - update to 1.168.7
start-client-core - update to 1.168.9
vue-router - update to 1.169.9
solid-router - update to 1.169.9
router-core - update to 1.169.9
react-router - update to 1.169.9
start-plugin-core - update to 1.169.27