Remote Code Execution Vulnerability in React-Tracked by Dai Shi
CVE-2026-48160

9.3CRITICAL

Key Information:

Vendor

Dai-shi

Vendor
CVE Published:
10 August 2026

What is CVE-2026-48160?

A severe vulnerability in React-Tracked was identified during a specific period in May 2026, where malicious commits were introduced to the default branch. These commits enabled attackers to execute remote code on developer machines through the 'npm install' command. While the malicious code was force-pushed from the repository, local clones, forks, and direct-SHA references may still harbor these commits. The attack targeted developer environments by fetching and executing JavaScript payloads from an attacker-controlled server without proper TLS verification. Users who ran 'npm install' between the specified dates should consider their machines compromised, rotate all accessible credentials, audit account activity from that time, and remove local clones.

Affected Version(s)

react-tracked >= 6978272a7d6ca02225cb747ea69f427512e33699, <= 949f1a3d6bb1ff7d1a0dec892afd773e742627e8

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.