THREAT OPS › Threat News › [NVD] CVE-2026-48161 — react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d1495a2505f9277da295a98cf176f4496 through 7b79148d1495a2505f9277da295a98cf176f4496 that executed remote attacker-controlled code on
[NVD] CVE-2026-48161 — react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d1495a2505f9277da295a98cf176f4496 through 7b79148d1495a2505f9277da295a98cf176f4496 that executed remote attacker-controlled code on
CVE-2026-48161 CVSS: None Published: 2026-08-10T23:16:51.343
react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d1495a2505f9277da295a98cf176f4496 through 7b79148d1495a2505f9277da295a98cf176f4496 that executed remote attacker-controlled code on developer machines during `npm install`. The commits were
MITRE ATT&CK techniques
- ServerlessT1583.007
- JavaScriptT1059.007
- ServerlessT1584.007
- ServerlessAML.T0008.004
Indicators of compromise
- 7b79148d1495a2505f9277da295a98cf176f4496sha1
- CVE-2026-48161cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-48161