Impact
A local attacker can manipulate the packageName argument passed to the installPackage function in TanStack devtools-vite, causing an operating system command to be injected and executed on the host system. The attack requires high complexity and is known to be difficult to exploit, but the vulnerability has been publicly disclosed and could be leveraged by an attacker with local privileges.
Affected Systems
TanStack devtools-vite version 0.7.0 is affected. No other product versions are listed as impacted.
Risk and Exploitability
The CVSS score is 2.0, indicating low overall severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local access, has a high complexity level, and is considered difficult. The attack vector is local, and no remote exploitation is documented.
OpenCVE Enrichment