Back

CVE-2026-45321

Source: nvd.nist.gov

Published:

<p>On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself

Read original article

Loading article...

Article not found