PatchSiren cyber security CVE debrief
CVE-2026-48160 dai-shi CVE debrief
CVE-2026-48160 was published on 2026-08-10T21:17:23.303Z and was last modified on 2026-09-09T20:55:04.493Z. The NVD entry is currently Deferred. A malicious code was added to the `react-tracked` package's default branch between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, which could execute remote attacker-controlled code on developer machines during `npm install`.
- Vendor
- dai-shi
- Product
- react-tracked
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-09-09
Who should care
Developers who installed the `react-tracked` package on their machines, especially those who ran `npm install` against an affected checkout on or after 2026-05-18 19:26:36, should treat the machine as compromised and take immediate action to rotate credentials, audit account activity, and verify the integrity of the package installation. Operators, platform administrators, vulnerability management teams, and security teams should also be aware of the and
Why it matters
CVE-2026-48160 is a critical vulnerability in the `react-tracked` package that could lead to remote code execution on developer machines during `npm install`. Developers who installed the package on their machines, especially those who ran `npm install` against an affected checkout, should treat the machine as compromised and take immediate action to rotate credentials, audit account activity, and verify the integrity of the package installation.
- Potential full compromise of machines reachable from a Node process with the user's permissions
- Need to rotate credentials and audit account activity
- Verification of `react-tracked` package installation integrity required
- Possible exposure of sensitive data or unauthorized access
Technical summary
A malicious code was added to the `react-tracked` package's default branch, which could execute remote attacker-controlled code on developer machines during `npm install`. The code fetched a JavaScript payload from an attacker-controlled HTTPS endpoint and evaluated it as code with `require` available. This vulnerability affects developers who installed the package on their machines, especially those who ran `npm install` against an affected checkout on or after 2026-05-18 19:26:36. The vulnerability has a high defensive priority.
Defensive priority
High
Recommended defensive actions
- Review and audit account activity since 2026-05-18 19:26:36
- Rotate every credential the machine could reach
- Clean local clones of the affected repository
- Verify the integrity of the `react-tracked` package installation
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD detail page provide information about the vulnerability. A GitHub security advisory also provides additional context. Evidence is limited to public sources and may not be comprehensive. Defenders should verify the integrity of the `react-tracked` package installation and review account activity since 2026-05-18 19:26:36.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48160 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48160
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48160 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48160
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/dai-shi/react-tracked/security/advisories/GHSA-79c5-q7m9-9c6x
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.