<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — TanStack</title><description>Actively exploited vulnerabilities affecting TanStack products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/tanstack.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-45321 — TanStack Unspecified Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-45321</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-45321</guid><description>This vulnerability allowed attackers to publish malicious versions of TanStack packages to the npm registry under the project&apos;s trusted identity. Because developers and build pipelines inherently trust packages from known publishers, this created a supply-chain attack vector where credential-stealing malware could be silently introduced into downstream projects. The fact that ransomware actors have leveraged this makes it especially severe — any environment that pulled affected package versions may have had credentials compromised.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><category>TanStack</category><category>TanStack</category></item></channel></rss>