CVE-2026-45321 — @tanstack arktype-adapter
CISA KEVRansomwareAs of 2026-05-28, CVE-2026-45321 is a CRITICAL-severity vulnerability in @tanstack arktype-adapter, CVSS v3.1 9.6, EPSS 15.0% (94.6th percentile). It is listed in the CISA Known Exploited Vulnerabilities catalog (added 2026-05-27), with a US federal remediation deadline of 2026-06-10, and CISA links it to known ransomware campaigns. Threadlinqs Intelligence links 4 tracked threat campaigns to CVE-2026-45321, most recently “Binding.gyp "Phantom Gyp" Supply Chain Attack (Miasma Worm) Enables CI/CD Worm Propagation Across 57 npm Packages”.
Last updated: 2026-05-28
What is CVE-2026-45321?
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.
The record classifies CVE-2026-45321 under weakness class CWE-506. Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs no prior authentication, needs a user to take an action first, and has high impact on confidentiality, integrity, availability. 10 affected-product entries are recorded, across 1 vendor, listed below. The identifier was first published 124 days ago.
Severity and exploitation probability
- CVSS v3.1 base score
- 9.6 — CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H - EPSS (FIRST)
- 15.0% probability of exploitation in the next 30 days, higher than 94.6% of all scored CVEs
- CISA KEV
- Listed since 2026-05-27, federal remediation deadline 2026-06-10 — used in known ransomware campaigns
- Threadlinqs priority
- 10/10 — CISA lists it as used in ransomware, which Threadlinqs scores at the maximum
- Published
- 2026-05-12, last modified 2026-05-28
Is CVE-2026-45321 being exploited?
CISA added CVE-2026-45321 to the Known Exploited Vulnerabilities catalog on 2026-05-27, which means the agency holds evidence of exploitation in the wild; US federal civilian agencies had to remediate it by 2026-06-10 under BOD 22-01. CISA flags the vulnerability as one used in known ransomware campaigns. It currently carries a trending score of 44 in the Threadlinqs vulnerability feed.
Affected products and versions
- @tanstack: arktype-adapter, eslint-plugin-router, eslint-plugin-start, history, nitro-v2-vite-plugin, react-router, react-router-devtools, react-router-ssr-query, react-start, react-start-client
How to fix CVE-2026-45321
Because CVE-2026-45321 is KEV-listed, US federal civilian agencies were required to apply the vendor fix, or stop using the product, by 2026-06-10. No vendor patch reference has been recorded for CVE-2026-45321 in the tracked sources. Follow the references below for a fix, and treat the products listed above as exposed until the vendor states otherwise.
Threat activity tracking CVE-2026-45321
4 tracked threats in the Threadlinqs corpus reference CVE-2026-45321, either in the campaign’s CVE list or as an indicator on the campaign record.
- Binding.gyp "Phantom Gyp" Supply Chain Attack (Miasma Worm) Enables CI/CD Worm Propagation Across 57 npm Packages — HIGH · 2026-06-04
- durabletask PyPI Supply Chain Compromise (v1.4.1–1.4.3) — Microsoft-Published Azure Durable Functions SDK Trojanized w/ Cross-Cloud Credential Stealer + Linux Disk Wiper (TeamPCP / Mini Shai-Hulud) — CRITICAL · 2026-05-25
- Nx Console VS Code Extension Backdoored (v18.95.0) — TeamPCP Mini Shai-Hulud Pivot from TanStack npm Worm to GitHub Internal Repository Breach (CVE-2026-48027) — CRITICAL · 2026-05-21
- TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payload — CRITICAL · 2026-03-31
Sources
Seeded from cveorg and not yet processed by the Threadlinqs enrichment pipeline, so blank CVSS, EPSS or KEV fields above mean NOT MEASURED rather than measured-absent.
← all vulnerabilities · Markdown version · Threadlinqs Intelligence