Skip to main content

Cybersecurity Weather

Global observatory

← Vulnerabilities

CVE-2026-45321

EPSS 2%KEV

TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.

Published
Last modified
CISA KEV
Yes
Ransomware use
Known

Official sources

CVE-2026-45321 | Cyber Weather Index