Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-45321

3 месяца назад

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-g7cv-rxg3-hmpx

3 месяца назад

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys

CVSS3: 9.6
EPSS: Низкий
fstec логотип

BDU:2026-06725

3 месяца назад

Уязвимость набора библиотек TanStack, связанная с наличием недекларированных возможностей, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-45321

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.

CVSS3: 9.6
2%
Низкий
3 месяца назад
github логотип
GHSA-g7cv-rxg3-hmpx

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys

CVSS3: 9.6
2%
Низкий
3 месяца назад
fstec логотип
BDU:2026-06725

Уязвимость набора библиотек TanStack, связанная с наличием недекларированных возможностей, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.6
2%
Низкий
3 месяца назад

Уязвимостей на страницу