CVE-2026-78177

Source
https://cve.org/CVERecord?id=CVE-2026-78177
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78177.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-78177
Published
2026-08-24T02:30:08.352Z
Modified
2026-08-25T04:02:58.616834185Z
Severity
  • 1.1 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
TanStack devtools-vite Development Devtools Event Bus package-manager.ts installPackage os command injection
Details

A vulnerability was found in TanStack devtools-vite 0.7.0. Affected by this issue is the function installPackage of the file packages/devtools-bundler-core/src/package-manager.ts of the component Development Devtools Event Bus. The manipulation of the argument packageName results in os command injection. Attacking locally is a requirement. A high complexity level is associated with this attack. The exploitation is known to be difficult. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78177.json",
    "cwe_ids": [
        "CWE-77",
        "CWE-78"
    ],
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/tanstack/devtools

Affected ranges

Type
GIT
Repo
https://github.com/tanstack/devtools
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.7.0"
        },
        {
            "last_affected": "0.7.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.7.0
@tanstack/devtools-event-client@0.*
@tanstack/devtools-event-client@0.3.0
@tanstack/react-devtools@0.*
@tanstack/react-devtools@0.7.0
@tanstack/solid-devtools@0.*
@tanstack/solid-devtools@0.7.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78177.json"