TanStack Start Patches Critical XSS Flaw
TanStack disclosed CVE-2026-102989, a critical reflected XSS vulnerability in server-function response handling that lets unauthenticated attackers craft URLs returning attacker-controlled HTML from an app’s origin. Patched releases are available now; affected apps must update, rebuild, and redeploy.
This is an urgent server-boundary fix, not a routine dependency bump: updating locally does nothing for already-deployed builds.
- –A victim only needs to open a crafted link, after which attacker JavaScript can act with their same-origin access.
- –Patched versions are `@tanstack/react-start` 1.168.60, `@tanstack/solid-start` 1.168.57, `@tanstack/vue-start` 1.168.56, and `@tanstack/start-server-core` 1.169.39.
- –Teams should verify the resolved lockfile versions, rebuild production artifacts, and redeploy immediately.
- –WAF or edge filtering can reduce exposure temporarily, but it is not a substitute for upgrading.
DISCOVERED
1h ago
2026-09-30
PUBLISHED
1h ago
2026-09-30
RELEVANCE
AUTHOR
tan_stack
