Skip to main content
EPSS 2.3%top 17%

CVE-2026-45321: CWE-506: Embedded Malicious Code in @tanstack arktype-adapter

0
Critical
VulnerabilityCVE-2026-45321cvecve-2026-45321cwe-506
Published: 05/12/2026 (05/12/2026, 00:12:35 UTC)
Source: CVE Database V5
Vendor/Project: @tanstack
Product: arktype-adapter

Description

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.

CVSS v3.1

Score 9.6critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected software

@tanstack

arktype-adapter

Affected versions
=1.166.12=1.166.15

@tanstack

eslint-plugin-router

Affected versions
=1.161.9=1.161.12

@tanstack

eslint-plugin-start

Affected versions
=0.0.4=0.0.7

@tanstack

history

Affected versions
=1.161.9=1.161.12

@tanstack

nitro-v2-vite-plugin

Affected versions
=1.154.12=1.154.15

@tanstack

react-router

Affected versions
=1.169.5=1.169.8

@tanstack

react-router-devtools

Affected versions
=1.166.16=1.166.19

@tanstack

react-router-ssr-query

Affected versions
=1.166.15=1.166.18

@tanstack

react-start

Affected versions
=1.167.68=1.167.71

@tanstack

react-start-client

Affected versions
=1.166.51=1.166.54

@tanstack

react-start-rsc

Affected versions
=0.0.47=0.0.50

@tanstack

react-start-server

Affected versions
=1.166.55=1.166.58

@tanstack

router-cli

Affected versions
=1.166.46=1.166.49

@tanstack

router-core

Affected versions
=1.169.5=1.169.8

@tanstack

router-devtools

Affected versions
=1.166.16=1.166.19

@tanstack

router-devtools-core

Affected versions
=1.167.6=1.167.9

@tanstack

router-generator

Affected versions
=1.166.45=1.166.48

@tanstack

router-plugin

Affected versions
=1.167.38=1.167.41

@tanstack

router-ssr-query-core

Affected versions
=1.168.3=1.168.6

@tanstack

router-utils

Affected versions
=1.161.11=1.161.14

@tanstack

outer-vite-plugin

Affected versions
=1.166.53=1.166.56

@tanstack

solid-router

Affected versions
=1.169.5=1.169.8

@tanstack

solid-router-devtools

Affected versions
=1.166.16=1.166.19

@tanstack

solid-router-ssr-query

Affected versions
=1.166.15=1.166.18

@tanstack

solid-start

Affected versions
=1.167.65=1.167.68

@tanstack

solid-start-client

Affected versions
=1.166.50=1.166.53

@tanstack

solid-start-server

Affected versions
=1.166.54=1.166.57

@tanstack

start-client-core

Affected versions
=1.168.5=1.168.8

@tanstack

start-fn-stubs

Affected versions
=1.161.9=1.161.12

@tanstack

start-plugin-core

Affected versions
=1.169.23=1.169.26

@tanstack

start-server-core

Affected versions
=1.167.33=1.167.36

@tanstack

start-static-server-functions

Affected versions
=1.166.44=1.166.47

@tanstack

start-storage-context

Affected versions
=1.166.38=1.166.41

@tanstack

valibot-adapter

Affected versions
=1.166.12=1.166.15

@tanstack

virtual-file-routes

Affected versions
=1.161.10=1.161.13

@tanstack

vue-router

Affected versions
=1.169.5=1.169.8

@tanstack

vue-router-devtools

Affected versions
=1.166.16=1.166.19

@tanstack

vue-router-ssr-query

Affected versions
=1.166.15=1.166.18

@tanstack

vue-start

Affected versions
=1.167.61=1.167.64

@tanstack

vue-start-client

Affected versions
=1.166.46=1.166.49

@tanstack

vue-start-server

Affected versions
=1.166.50=1.166.53

@tanstack

zod-adapter

Affected versions
=1.166.12=1.166.15
@tanstack/arktype-adapter
pkg:npm/@tanstack/arktype-adapter
Affected versions
=1.166.12=1.166.15

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/04/2026, 13:26:12 UTC

Technical Analysis

CVE-2026-45321 describes a supply chain attack on the @tanstack npm packages, including arktype-adapter, where an attacker leveraged a combination of a pull_request_target misconfiguration, GitHub Actions cache poisoning, and runtime memory extraction of OIDC tokens to publish malicious versions under a trusted identity. This attack resulted in 84 malicious versions being published across 42 packages, each receiving two malicious versions. The attack exploited the trusted GitHub Actions OIDC publisher binding without modifying the publish workflow itself. The affected versions of @tanstack/arktype-adapter are exactly 1.166.12 and 1.166.15. The CVSS score is 9.6 (critical), indicating high impact on confidentiality, integrity, and availability.

Potential Impact

The attack allows an adversary to publish malicious code under a trusted identity, potentially leading to credential theft and compromise of systems that consume the affected packages. The high CVSS score (9.6) reflects critical impact on confidentiality, integrity, and availability. This compromises the software supply chain trust for the affected @tanstack packages, including arktype-adapter versions 1.166.12 and 1.166.15.

Mitigation Recommendations

No official patch or remediation level has been provided yet. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid using the affected versions (=1.166.12 and =1.166.15) of @tanstack/arktype-adapter and related packages. Monitor vendor channels for updates and consider verifying package integrity through alternative means.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-05-11T20:50:30.539Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a028743cbff5d86108b505d

Added to database: 05/12/2026, 01:49:55 UTC

Last enriched: 08/04/2026, 13:26:12 UTC

Last updated: 09/13/2026, 22:01:34 UTC

Views: 354

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses