@tanstack vendor intelligence
@tanstack Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting @tanstack products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 1
- Known exploited vulnerabilities affecting @tanstack products
- In CISA KEV
- 1
- Records also listed in the official catalog
- Beyond CISA KEV
- 0
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- @tanstack KEVs with sensor-observed exploitation activity
The catalog gap matters for @tanstack exposure
All one exploited @tanstack CVEs tracked here are also listed in CISA KEV. Use product ownership and sensor evidence to prioritize within this portfolio.
- 100%
- Covered by CISA
- 0%
- Beyond CISA
- 1
- Product families
Attested @tanstack CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-45321
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys |
arktype-adapter, eslint-plugin-router, eslint-plugin-start, history, nitro-v2-vite-plugin, react-router, react-router-devtools, react-router-ssr-query, react-start, react-start-client, react-start-rsc, react-start-server, router-cli, router-core, router-devtools, router-devtools-core, router-generator, router-plugin, router-ssr-query-core, router-utils, outer-vite-plugin, solid-router, solid-router-devtools, solid-router-ssr-query, solid-start, solid-start-client, solid-start-server, start-client-core, start-fn-stubs, start-plugin-core, start-server-core, start-static-server-functions, start-storage-context, valibot-adapter, virtual-file-routes, vue-router, vue-router-devtools, vue-router-ssr-query, vue-start, vue-start-client, vue-start-server, zod-adapter | Confirmed | In CISA | 27 May 2026 |
No @tanstack CVEs match this search or filter.
Showing 1 of 1 @tanstack known exploited vulnerabilities.
Recurring weakness patterns
Embedded malicious code account for one mapped occurrence across this @tanstack KEV portfolio.
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.