Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-45321

Published 2026-05-12
Updated 3 months ago
Vendor/s
TanStack
Product/s
TanStack
Version/s
1.166.12
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.6
/ 10
Critical
Severity Details
Base score
9.6 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Description

Critical supply chain attack (CVSS 9.6) affecting TanStack npm packages. Malicious versions published via GitHub Actions. Active exploitation reported.

CPE

TanStack logo
TanStack
Product Version Start Version End (excl.) Status
tanstack\/arktype-adapter 1.166.12 1.166.12 vulnerable
tanstack\/arktype-adapter 1.166.15 1.166.15 vulnerable
tanstack\/eslint-plugin-router 1.161.9 1.161.9 vulnerable
tanstack\/eslint-plugin-router 1.161.12 1.161.12 vulnerable
tanstack\/eslint-plugin-start 0.0.4 0.0.4 vulnerable
tanstack\/eslint-plugin-start 0.0.7 0.0.7 vulnerable
tanstack\/history 1.161.9 1.161.9 vulnerable
tanstack\/history 1.161.12 1.161.12 vulnerable
tanstack\/nitro-v2-vite-plugin 1.154.12 1.154.12 vulnerable
tanstack\/nitro-v2-vite-plugin 1.154.15 1.154.15 vulnerable
tanstack\/react-router 1.169.5 1.169.5 vulnerable
tanstack\/react-router 1.169.8 1.169.8 vulnerable
tanstack\/react-router-devtools 1.166.16 1.166.16 vulnerable
tanstack\/react-router-devtools 1.166.19 1.166.19 vulnerable
tanstack\/react-router-ssr-query 1.166.15 1.166.15 vulnerable
tanstack\/react-router-ssr-query 1.166.18 1.166.18 vulnerable
tanstack\/react-start 1.167.68 1.167.68 vulnerable
tanstack\/react-start 1.167.71 1.167.71 vulnerable
tanstack\/react-start-client 1.166.51 1.166.51 vulnerable
tanstack\/react-start-client 1.166.54 1.166.54 vulnerable
tanstack\/react-start-rsc 0.0.47 0.0.47 vulnerable
tanstack\/react-start-rsc 0.0.50 0.0.50 vulnerable
tanstack\/react-start-server 1.166.55 1.166.55 vulnerable
tanstack\/react-start-server 1.166.58 1.166.58 vulnerable
tanstack\/router-cli 1.166.46 1.166.46 vulnerable
tanstack\/router-cli 1.166.49 1.166.49 vulnerable
tanstack\/router-core 1.169.5 1.169.5 vulnerable
tanstack\/router-core 1.169.8 1.169.8 vulnerable
tanstack\/router-devtools 1.166.16 1.166.16 vulnerable
tanstack\/router-devtools 1.166.19 1.166.19 vulnerable
tanstack\/router-devtools-core 1.167.6 1.167.6 vulnerable
tanstack\/router-devtools-core 1.167.9 1.167.9 vulnerable
tanstack\/router-generator 1.166.45 1.166.45 vulnerable
tanstack\/router-generator 1.166.48 1.166.48 vulnerable
tanstack\/router-plugin 1.167.38 1.167.38 vulnerable
tanstack\/router-plugin 1.167.41 1.167.41 vulnerable
tanstack\/router-ssr-query-core 1.168.3 1.168.3 vulnerable
tanstack\/router-ssr-query-core 1.168.6 1.168.6 vulnerable
tanstack\/router-utils 1.161.11 1.161.11 vulnerable
tanstack\/router-utils 1.161.14 1.161.14 vulnerable
tanstack\/router-vite-plugin 1.166.53 1.166.53 vulnerable
tanstack\/router-vite-plugin 1.166.56 1.166.56 vulnerable
tanstack\/solid-router 1.169.5 1.169.5 vulnerable
tanstack\/solid-router 1.169.8 1.169.8 vulnerable
tanstack\/solid-router-devtools 1.166.16 1.166.16 vulnerable
tanstack\/solid-router-devtools 1.166.19 1.166.19 vulnerable
tanstack\/solid-router-ssr-query 1.166.15 1.166.15 vulnerable
tanstack\/solid-router-ssr-query 1.166.18 1.166.18 vulnerable
tanstack\/solid-start 1.167.65 1.167.65 vulnerable
tanstack\/solid-start 1.167.68 1.167.68 vulnerable
tanstack\/solid-start-client 1.166.50 1.166.50 vulnerable
tanstack\/solid-start-client 1.166.53 1.166.53 vulnerable
tanstack\/solid-start-server 1.166.54 1.166.54 vulnerable
tanstack\/solid-start-server 1.166.57 1.166.57 vulnerable
tanstack\/start-client-core 1.168.5 1.168.5 vulnerable
tanstack\/start-client-core 1.168.8 1.168.8 vulnerable
tanstack\/start-fn-stubs 1.161.9 1.161.9 vulnerable
tanstack\/start-fn-stubs 1.161.12 1.161.12 vulnerable
tanstack\/start-plugin-core 1.169.23 1.169.23 vulnerable
tanstack\/start-plugin-core 1.169.26 1.169.26 vulnerable
tanstack\/start-server-core 1.167.33 1.167.33 vulnerable
tanstack\/start-server-core 1.167.36 1.167.36 vulnerable
tanstack\/start-static-server-functions 1.166.44 1.166.44 vulnerable
tanstack\/start-static-server-functions 1.166.47 1.166.47 vulnerable
tanstack\/start-storage-context 1.166.38 1.166.38 vulnerable
tanstack\/start-storage-context 1.166.41 1.166.41 vulnerable
tanstack\/valibot-adapter 1.166.12 1.166.12 vulnerable
tanstack\/valibot-adapter 1.166.15 1.166.15 vulnerable
tanstack\/virtual-file-routes 1.161.10 1.161.10 vulnerable
tanstack\/virtual-file-routes 1.161.13 1.161.13 vulnerable
tanstack\/vue-router 1.169.5 1.169.5 vulnerable
tanstack\/vue-router 1.169.8 1.169.8 vulnerable
tanstack\/vue-router-devtools 1.166.16 1.166.16 vulnerable
tanstack\/vue-router-devtools 1.166.19 1.166.19 vulnerable
tanstack\/vue-router-ssr-query 1.166.15 1.166.15 vulnerable
tanstack\/vue-router-ssr-query 1.166.18 1.166.18 vulnerable
tanstack\/vue-start 1.167.61 1.167.61 vulnerable
tanstack\/vue-start 1.167.64 1.167.64 vulnerable
tanstack\/vue-start-client 1.166.46 1.166.46 vulnerable
tanstack\/vue-start-client 1.166.49 1.166.49 vulnerable
tanstack\/vue-start-server 1.166.50 1.166.50 vulnerable
tanstack\/vue-start-server 1.166.53 1.166.53 vulnerable
tanstack\/zod-adapter 1.166.12 1.166.12 vulnerable
tanstack\/zod-adapter 1.166.15 1.166.15 vulnerable
mistralai 2.4.6 2.4.6 vulnerable
mistralai\/mistralai 2.2.3 2.2.3 vulnerable
mistralai\/mistralai 2.2.4 2.2.4 vulnerable
mistralai\/mistralai-azure 1.7.2 1.7.2 vulnerable
mistralai\/mistralai-azure 1.7.3 1.7.3 vulnerable
mistralai\/mistralai-gcp 1.7.2 1.7.2 vulnerable
mistralai\/mistralai-gcp 1.7.3 1.7.3 vulnerable
ml-toolkit-ts 1.0.4 1.0.4 vulnerable
ml-toolkit-ts 1.0.5 1.0.5 vulnerable
ml-toolkit-ts\/preprocessing 1.0.2 1.0.2 vulnerable
ml-toolkit-ts\/preprocessing 1.0.3 1.0.3 vulnerable
ml-toolkit-ts\/xgboost 1.0.3 1.0.3 vulnerable
ml-toolkit-ts\/xgboost 1.0.4 1.0.4 vulnerable
beproduct\/nestjs-auth 0.1.2 0.1.2 vulnerable
beproduct\/nestjs-auth 0.1.3 0.1.3 vulnerable
beproduct\/nestjs-auth 0.1.4 0.1.4 vulnerable
beproduct\/nestjs-auth 0.1.5 0.1.5 vulnerable
beproduct\/nestjs-auth 0.1.6 0.1.6 vulnerable
beproduct\/nestjs-auth 0.1.7 0.1.7 vulnerable
beproduct\/nestjs-auth 0.1.8 0.1.8 vulnerable
beproduct\/nestjs-auth 0.1.9 0.1.9 vulnerable
beproduct\/nestjs-auth 0.1.10 0.1.10 vulnerable
beproduct\/nestjs-auth 0.1.11 0.1.11 vulnerable
beproduct\/nestjs-auth 0.1.12 0.1.12 vulnerable
beproduct\/nestjs-auth 0.1.13 0.1.13 vulnerable
beproduct\/nestjs-auth 0.1.14 0.1.14 vulnerable
beproduct\/nestjs-auth 0.1.15 0.1.15 vulnerable
beproduct\/nestjs-auth 0.1.16 0.1.16 vulnerable
beproduct\/nestjs-auth 0.1.17 0.1.17 vulnerable
beproduct\/nestjs-auth 0.1.19 0.1.19 vulnerable
git-git-git 1.0.8 1.0.8 vulnerable
git-git-git 1.0.9 1.0.9 vulnerable
git-git-git 1.0.10 1.0.10 vulnerable
git-git-git 1.0.12 1.0.12 vulnerable
git_branch_selector 1.3.3 1.3.3 vulnerable
git_branch_selector 1.3.4 1.3.4 vulnerable
git_branch_selector 1.3.5 1.3.5 vulnerable
git_branch_selector 1.3.7 1.3.7 vulnerable
nextmove-mcp 0.1.3 0.1.3 vulnerable
nextmove-mcp 0.1.4 0.1.4 vulnerable
nextmove-mcp 0.1.5 0.1.5 vulnerable
nextmove-mcp 0.1.7 0.1.7 vulnerable
tolka\/cli 1.0.2 1.0.2 vulnerable
tolka\/cli 1.0.3 1.0.3 vulnerable
tolka\/cli 1.0.4 1.0.4 vulnerable
tolka\/cli 1.0.6 1.0.6 vulnerable
cmux-agent-mcp 0.1.3 0.1.3 vulnerable
cmux-agent-mcp 0.1.4 0.1.4 vulnerable
cmux-agent-mcp 0.1.5 0.1.5 vulnerable
cmux-agent-mcp 0.1.6 0.1.6 vulnerable
cmux-agent-mcp 0.1.7 0.1.7 vulnerable
cmux-agent-mcp 0.1.8 0.1.8 vulnerable
supersurkhet\/cli 0.0.2 0.0.2 vulnerable
supersurkhet\/cli 0.0.3 0.0.3 vulnerable
supersurkhet\/cli 0.0.4 0.0.4 vulnerable
supersurkhet\/cli 0.0.5 0.0.5 vulnerable
supersurkhet\/cli 0.0.6 0.0.6 vulnerable
supersurkhet\/cli 0.0.7 0.0.7 vulnerable
supersurkhet\/sdk 0.0.2 0.0.2 vulnerable
supersurkhet\/sdk 0.0.3 0.0.3 vulnerable
supersurkhet\/sdk 0.0.4 0.0.4 vulnerable
supersurkhet\/sdk 0.0.5 0.0.5 vulnerable
supersurkhet\/sdk 0.0.6 0.0.6 vulnerable
supersurkhet\/sdk 0.0.7 0.0.7 vulnerable
taskflow-corp\/cli 0.1.24 0.1.24 vulnerable
taskflow-corp\/cli 0.1.25 0.1.25 vulnerable
taskflow-corp\/cli 0.1.26 0.1.26 vulnerable
taskflow-corp\/cli 0.1.27 0.1.27 vulnerable
taskflow-corp\/cli 0.1.28 0.1.28 vulnerable
taskflow-corp\/cli 0.1.29 0.1.29 vulnerable
tallyui\/components 1.0.1 1.0.1 vulnerable
tallyui\/components 1.0.2 1.0.2 vulnerable
tallyui\/components 1.0.3 1.0.3 vulnerable
tallyui\/connector-medusa 1.0.1 1.0.1 vulnerable
tallyui\/connector-medusa 1.0.2 1.0.2 vulnerable
tallyui\/connector-medusa 1.0.3 1.0.3 vulnerable
tallyui\/connector-shopify 1.0.1 1.0.1 vulnerable
tallyui\/connector-shopify 1.0.2 1.0.2 vulnerable
tallyui\/connector-shopify 1.0.3 1.0.3 vulnerable
tallyui\/connector-vendure 1.0.1 1.0.1 vulnerable
tallyui\/connector-vendure 1.0.2 1.0.2 vulnerable
tallyui\/connector-vendure 1.0.3 1.0.3 vulnerable
tallyui\/connector-woocommerce 1.0.1 1.0.1 vulnerable
tallyui\/connector-woocommerce 1.0.2 1.0.2 vulnerable
tallyui\/connector-woocommerce 1.0.3 1.0.3 vulnerable
tallyui\/core 0.2.1 0.2.1 vulnerable
tallyui\/core 0.2.2 0.2.2 vulnerable
tallyui\/core 0.2.3 0.2.3 vulnerable
tallyui\/database 1.0.1 1.0.1 vulnerable
tallyui\/database 1.0.2 1.0.2 vulnerable
tallyui\/database 1.0.3 1.0.3 vulnerable
tallyui\/pos 0.1.1 0.1.1 vulnerable
tallyui\/pos 0.1.2 0.1.2 vulnerable
tallyui\/pos 0.1.3 0.1.3 vulnerable
tallyui\/storage-sqlite 0.2.1 0.2.1 vulnerable
tallyui\/storage-sqlite 0.2.2 0.2.2 vulnerable
tallyui\/storage-sqlite 0.2.3 0.2.3 vulnerable
tallyui\/theme 0.2.1 0.2.1 vulnerable
tallyui\/theme 0.2.2 0.2.2 vulnerable
tallyui\/theme 0.2.3 0.2.3 vulnerable
draftauth\/client 0.2.1 0.2.1 vulnerable
draftauth\/client 0.2.2 0.2.2 vulnerable
draftauth\/core 0.13.1 0.13.1 vulnerable
draftauth\/core 0.13.2 0.13.2 vulnerable
draftlab\/auth 0.24.1 0.24.1 vulnerable
draftlab\/auth 0.24.2 0.24.2 vulnerable
draftlab\/auth-router 0.5.1 0.5.1 vulnerable
draftlab\/auth-router 0.5.2 0.5.2 vulnerable
draftlab\/db 0.16.1 0.16.1 vulnerable
draftlab\/db 0.16.2 0.16.2 vulnerable
simple_type-safe_actions 0.8.3 0.8.3 vulnerable
simple_type-safe_actions 0.8.4 0.8.4 vulnerable
cross-stitch 1.1.3 1.1.3 vulnerable
cross-stitch 1.1.4 1.1.4 vulnerable
cross-stitch 1.1.6 1.1.6 vulnerable
squawk\/airports 0.6.2 0.6.2 vulnerable
squawk\/airports 0.6.3 0.6.3 vulnerable
squawk\/airports 0.6.5 0.6.5 vulnerable
squawk\/airspace 0.8.1 0.8.1 vulnerable
squawk\/airspace 0.8.2 0.8.2 vulnerable
squawk\/airspace 0.8.4 0.8.4 vulnerable
squawk\/airspace-data 0.5.3 0.5.3 vulnerable
squawk\/airspace-data 0.5.4 0.5.4 vulnerable
squawk\/airspace-data 0.5.6 0.5.6 vulnerable
squawk\/airway-data 0.5.4 0.5.4 vulnerable
squawk\/airway-data 0.5.5 0.5.5 vulnerable
squawk\/airway-data 0.5.7 0.5.7 vulnerable
squawk\/airways 0.4.2 0.4.2 vulnerable
squawk\/airways 0.4.3 0.4.3 vulnerable
squawk\/airways 0.4.5 0.4.5 vulnerable
squawk\/fix-data 0.6.4 0.6.4 vulnerable
squawk\/fix-data 0.6.5 0.6.5 vulnerable
squawk\/fix-data 0.6.7 0.6.7 vulnerable
squawk\/fixes 0.3.2 0.3.2 vulnerable
squawk\/fixes 0.3.3 0.3.3 vulnerable
squawk\/fixes 0.3.5 0.3.5 vulnerable
squawk\/flight-math 0.5.4 0.5.4 vulnerable
squawk\/flight-math 0.5.5 0.5.5 vulnerable
squawk\/flight-math 0.5.7 0.5.7 vulnerable
squawk\/flightplan 0.5.2 0.5.2 vulnerable
squawk\/flightplan 0.5.3 0.5.3 vulnerable
squawk\/flightplan 0.5.5 0.5.5 vulnerable
squawk\/geo 0.4.4 0.4.4 vulnerable
squawk\/geo 0.4.5 0.4.5 vulnerable
squawk\/geo 0.4.7 0.4.7 vulnerable
squawk\/icao-registry 0.5.2 0.5.2 vulnerable
squawk\/icao-registry 0.5.3 0.5.3 vulnerable
squawk\/icao-registry 0.5.5 0.5.5 vulnerable
squawk\/icao-registry-data 0.8.4 0.8.4 vulnerable
squawk\/icao-registry-data 0.8.5 0.8.5 vulnerable
squawk\/icao-registry-data 0.8.7 0.8.7 vulnerable
squawk\/mcp 0.9.1 0.9.1 vulnerable
squawk\/mcp 0.9.2 0.9.2 vulnerable
squawk\/mcp 0.9.4 0.9.4 vulnerable
squawk\/navaid-data 0.6.4 0.6.4 vulnerable
squawk\/navaid-data 0.6.5 0.6.5 vulnerable
squawk\/navaid-data 0.6.7 0.6.7 vulnerable
squawk\/navaids 0.4.2 0.4.2 vulnerable
squawk\/navaids 0.4.3 0.4.3 vulnerable
squawk\/navaids 0.4.5 0.4.5 vulnerable
squawk\/notams 0.3.6 0.3.6 vulnerable
squawk\/notams 0.3.7 0.3.7 vulnerable
squawk\/notams 0.3.9 0.3.9 vulnerable
squawk\/procedure-data 0.7.3 0.7.3 vulnerable
squawk\/procedure-data 0.7.4 0.7.4 vulnerable
squawk\/procedure-data 0.7.6 0.7.6 vulnerable
squawk\/procedures 0.5.2 0.5.2 vulnerable
squawk\/procedures 0.5.3 0.5.3 vulnerable
squawk\/procedures 0.5.5 0.5.5 vulnerable
squawk\/types 0.8.1 0.8.1 vulnerable
squawk\/types 0.8.2 0.8.2 vulnerable
squawk\/types 0.8.4 0.8.4 vulnerable
squawk\/units 0.4.3 0.4.3 vulnerable
squawk\/units 0.4.4 0.4.4 vulnerable
squawk\/units 0.4.6 0.4.6 vulnerable
squawk\/weather 0.5.6 0.5.6 vulnerable
squawk\/weather 0.5.7 0.5.7 vulnerable
squawk\/weather 0.5.9 0.5.9 vulnerable
ts-dna 3.0.1 3.0.1 vulnerable
ts-dna 3.0.2 3.0.2 vulnerable
ts-dna 3.0.4 3.0.4 vulnerable
wot-api 0.8.1 0.8.1 vulnerable
wot-api 0.8.2 0.8.2 vulnerable
wot-api 0.8.4 0.8.4 vulnerable
agentwork-cli 0.1.4 0.1.4 vulnerable
agentwork-cli 0.1.5 0.1.5 vulnerable
dirigible-ai\/sdk 0.6.2 0.6.2 vulnerable
dirigible-ai\/sdk 0.6.3 0.6.3 vulnerable
guardrails_ai 0.10.1 0.10.1 vulnerable
opensearch 3.6.2 3.6.2 vulnerable
mesadev\/rest 0.28.3 0.28.3 vulnerable
mesadev\/saguaro 0.4.22 0.4.22 vulnerable
mesadev\/sdk 0.28.3 0.28.3 vulnerable
uipath\/access-policy-sdk 0.3.1 0.3.1 vulnerable
uipath\/access-policy-tool 0.3.1 0.3.1 vulnerable
uipath\/admin-tool 0.1.1 0.1.1 vulnerable
uipath\/agent-sdk 1.0.2 1.0.2 vulnerable
uipath\/agent-tool 1.0.1 1.0.1 vulnerable
uipath\/agent.sdk 0.0.18 0.0.18 vulnerable
uipath\/aops-policy-tool 0.3.1 0.3.1 vulnerable
uipath\/ap-chat 1.5.7 1.5.7 vulnerable
uipath\/api-workflow-tool 1.0.1 1.0.1 vulnerable
uipath\/apollo-core 5.9.2 5.9.2 vulnerable
uipath\/apollo-react 4.24.5 4.24.5 vulnerable
uipath\/apollo-wind 2.16.2 2.16.2 vulnerable
uipath\/auth 1.0.1 1.0.1 vulnerable
uipath\/case-tool 1.0.1 1.0.1 vulnerable
uipath\/cli 1.0.1 1.0.1 vulnerable
uipath\/codedagent-tool 1.0.1 1.0.1 vulnerable
uipath\/codedagents-tool 0.1.12 0.1.12 vulnerable
uipath\/codedapp-tool 1.0.1 1.0.1 vulnerable
uipath\/common 1.0.1 1.0.1 vulnerable
uipath\/context-grounding-tool 0.1.1 0.1.1 vulnerable
uipath\/data-fabric-tool 1.0.2 1.0.2 vulnerable
uipath\/docsai-tool 1.0.1 1.0.1 vulnerable
uipath\/filesystem 1.0.1 1.0.1 vulnerable
uipath\/flow-tool 1.0.2 1.0.2 vulnerable
uipath\/functions-tool 1.0.1 1.0.1 vulnerable
uipath\/gov-tool 0.3.1 0.3.1 vulnerable
uipath\/identity-tool 0.1.1 0.1.1 vulnerable
uipath\/insights-sdk 1.0.1 1.0.1 vulnerable
uipath\/insights-tool 1.0.1 1.0.1 vulnerable
uipath\/integrationservice-sdk 1.0.2 1.0.2 vulnerable
uipath\/integrationservice-tool 1.0.2 1.0.2 vulnerable
uipath\/llmgw-tool 1.0.1 1.0.1 vulnerable
uipath\/maestro-sdk 1.0.1 1.0.1 vulnerable
uipath\/maestro-tool 1.0.1 1.0.1 vulnerable
uipath\/orchestrator-tool 1.0.1 1.0.1 vulnerable
uipath\/packager-tool-apiworkflow 0.0.19 0.0.19 vulnerable
uipath\/packager-tool-bpmn 0.0.9 0.0.9 vulnerable
uipath\/packager-tool-case 0.0.9 0.0.9 vulnerable
uipath\/packager-tool-connector 0.0.19 0.0.19 vulnerable
uipath\/packager-tool-flow 0.0.19 0.0.19 vulnerable
uipath\/packager-tool-functions 0.1.1 0.1.1 vulnerable
uipath\/packager-tool-webapp 1.0.6 1.0.6 vulnerable
uipath\/packager-tool-workflowcompiler 0.0.16 0.0.16 vulnerable
uipath\/packager-tool-workflowcompiler-browser 0.0.34 0.0.34 vulnerable
uipath\/platform-tool 1.0.1 1.0.1 vulnerable
uipath\/project-packager 1.1.16 1.1.16 vulnerable
uipath\/resource-tool 1.0.1 1.0.1 vulnerable
uipath\/resourcecatalog-tool 0.1.1 0.1.1 vulnerable
uipath\/resources-tool 0.1.11 0.1.11 vulnerable
uipath\/robot 1.3.4 1.3.4 vulnerable
uipath\/rpa-legacy-tool 1.0.1 1.0.1 vulnerable
uipath\/rpa-tool 0.9.5 0.9.5 vulnerable
uipath\/solution-packager 0.0.35 0.0.35 vulnerable
uipath\/solution-tool 1.0.1 1.0.1 vulnerable
uipath\/solutionpackager-sdk 1.0.11 1.0.11 vulnerable
uipath\/solutionpackager-tool-core 0.0.34 0.0.34 vulnerable
uipath\/tasks-tool 1.0.1 1.0.1 vulnerable
uipath\/telemetry 0.0.7 0.0.7 vulnerable
uipath\/test-manager-tool 1.0.2 1.0.2 vulnerable
uipath\/tool-workflowcompiler 0.0.12 0.0.12 vulnerable
uipath\/traces-tool 1.0.1 1.0.1 vulnerable
uipath\/ui-widgets-multi-file-upload 1.0.1 1.0.1 vulnerable
uipath\/uipath-python-bridge 1.0.1 1.0.1 vulnerable
uipath\/vertical-solutions-tool 1.0.1 1.0.1 vulnerable
uipath\/vss 0.1.6 0.1.6 vulnerable
uipath\/widget.sdk 1.2.3 1.2.3 vulnerable

Related weakness (CWE)

CWE-506

Remediation plan

1

Apply official patches

Immediately update all @tanstack/* npm packages to the latest verified clean versions. TanStack has removed the malicious versions from the npm registry and released patched updates that secure the GitHub Actions workflow.

2

Update affected systems

Ensure systems are not using compromised versions such as @tanstack/react-router 1.169.5 or 1.169.8, @tanstack/router-core 1.169.5 or 1.169.8, and @tanstack/history 1.161.9 or 1.161.12.

3

Restrict access

Audit and rotate all secrets, environment variables, and credentials (e.g., AWS keys, npm tokens) that were accessible to CI/CD pipelines or developer environments where the malicious packages were installed or executed.

4

Monitor for exploitation

Review network egress logs for suspicious outbound connections to unknown IP addresses or domains, which may indicate credential exfiltration. Perform a full audit of your GitHub Actions 'pull_request_target' configurations.

Detection Guidance

Detection should focus on identifying the installation of specific malicious package versions published between 19:20 and 19:26 UTC on May 11, 2026. Security teams should scan package-lock.json or yarn.lock files for the affected @tanstack versions. Additionally, monitor for unusual runtime behavior in build environments, such as unexpected memory access patterns or unauthorized attempts to access OIDC tokens and environment secrets.

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management