Finding
indicator:15107:descriptionWhat happened
CISA KEV describes CVE-2026-45321 as: TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.