CVE Feed

    Dashboard / CVE / CVE-2026-15607

    CVE-2026-15607

    A vulnerability was detected in tanstack db up to 0.6.8. Affected by this vulnerability is the function select of the file src/query/compiler/select.ts of the component Alias Path Handler. The manipulation results in improperly controlled modification of object prototype attributes. The attack may be launched remotely. The exploit is now public and may be used. The patch is identified as ac09b1177a100eafa85cba3cd09dd1f53f933ded. A patch should be applied to remediate this issue.

    Published:Jul 13, 2026
    Last Modified:Jul 15, 2026
    EPS:Jul 13, 2026
    EPSS Score:0.00254
    CVSS Score:4.3

    Affected Products

    Vendor
    Tanstack
    Product
    Db

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High