CVE-2026-78177 | TanStack devtools-vite 0.7.0 Development Devtools Event Bus package-manager.ts installPackage packageName os command injection (Issue 464)
A vulnerability described as problematic has been identified in TanStack devtools-vite 0.7.0. Affected by this issue is the function installPackage of the file packages/devtools-bundler-core/src/package-manager.ts of the component Development Devtools Event Bus. The manipulation of the argument packageName results in os command injection.
This vulnerability is known as CVE-2026-78177. Attacking locally is a requirement. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More