QSearchQSearch

CVE-2026-45321

9.6 CRITICAL

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm ...

Published: 2026-05-12 · Last updated: 2026-05-29

Severity and scoring

CVSS
9.6 CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CWE
CWE-506

Affected products

VendorProduct
abhishake1agentwork-cli, beproduct\/nestjs-auth, cmux-agent-mcp
agentworkhqagentwork-cli, beproduct\/nestjs-auth, cmux-agent-mcp
antoinebcxagentwork-cli, beproduct\/nestjs-auth, cmux-agent-mcp
beproductagentwork-cli, beproduct\/nestjs-auth, cmux-agent-mcp
christianalaresagentwork-cli, beproduct\/nestjs-auth, cmux-agent-mcp
dirigibleagentwork-cli, beproduct\/nestjs-auth, cmux-agent-mcp
guardrailsaiagentwork-cli, beproduct\/nestjs-auth, cmux-agent-mcp
kilbotagentwork-cli, beproduct\/nestjs-auth, cmux-agent-mcp
linuxfoundationagentwork-cli, beproduct\/nestjs-auth, cmux-agent-mcp
matheuspergoliagentwork-cli, beproduct\/nestjs-auth, cmux-agent-mcp
mesaagentwork-cli, beproduct\/nestjs-auth, cmux-agent-mcp
mistralagentwork-cli, beproduct\/nestjs-auth, cmux-agent-mcp
multiagentcognitionagentwork-cli, beproduct\/nestjs-auth, cmux-agent-mcp
neilcochranagentwork-cli, beproduct\/nestjs-auth, cmux-agent-mcp
tanstackagentwork-cli, beproduct\/nestjs-auth, cmux-agent-mcp
uipathagentwork-cli, beproduct\/nestjs-auth, cmux-agent-mcp

Description

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-45758 Guardrails AI is a Python framework that helps build AI applications (9.6 CRITICAL)
  • CVE-2026-44477 CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments (9.9 CRITICAL)
  • CVE-2026-44247 Volcano is a Kubernetes-native batch scheduling system (6.8 MEDIUM)
  • CVE-2026-44374 Backstage is an open framework for building developer portals (4.3 MEDIUM)
  • CVE-2026-37531 AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-... (9.8 CRITICAL)

Same CWE

  • CVE-2026-45758 Guardrails AI is a Python framework that helps build AI applications (9.6 CRITICAL)
  • CVE-2026-48027 Nx Console is the user interface for Nx & Lerna (9.8 CRITICAL)
  • CVE-2026-8398 A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.24... (9.8 CRITICAL)
  • CVE-2026-44484 PyTorch Lightning is a deep learning framework to pretrain and finetune AI models (9.8 CRITICAL)