TanStack Supply Chain Attack Security Advisory (CVE-2026-45321)
TanStack has released a security update to address a supply-chain attack (compromised distribution path) issue in its products. the issue has been identified as CVE-2026-45321. affected are multiple @tanstack/* packages. examples include the @tanstack/react-router, @tanstack/solid-router, @tanstack/vue-router, and @tanstack/start families, as well as various devtools, adapter, and plugin packages. vulnerable versions

