YOU ARE VIEWING ONE ITEM FROM THE AICRIER FEED

TanStack Start Patches Critical XSS Flaw

AICrier tracks AI developer news across Product Hunt, GitHub, Hacker News, YouTube, X, arXiv, and more. This page keeps the article you opened front and center while giving you a path into the live feed.

// WHAT AICRIER DOES

7+

TRACKED FEEDS

24/7

SCRAPED FEED

Short summaries, external links, screenshots, relevance scoring, tags, and featured picks for AI builders.

TanStack Start Patches Critical XSS Flaw
OPEN LINK ↗
// 1h agoSECURITY INCIDENT

TanStack Start Patches Critical XSS Flaw

TanStack disclosed CVE-2026-102989, a critical reflected XSS vulnerability in server-function response handling that lets unauthenticated attackers craft URLs returning attacker-controlled HTML from an app’s origin. Patched releases are available now; affected apps must update, rebuild, and redeploy.

// ANALYSIS

This is an urgent server-boundary fix, not a routine dependency bump: updating locally does nothing for already-deployed builds.

  • –A victim only needs to open a crafted link, after which attacker JavaScript can act with their same-origin access.
  • –Patched versions are `@tanstack/react-start` 1.168.60, `@tanstack/solid-start` 1.168.57, `@tanstack/vue-start` 1.168.56, and `@tanstack/start-server-core` 1.169.39.
  • –Teams should verify the resolved lockfile versions, rebuild production artifacts, and redeploy immediately.
  • –WAF or edge filtering can reduce exposure temporarily, but it is not a substitute for upgrading.
// TAGS
tanstack-startsecurityframeworkdevtoolopen-source

DISCOVERED

1h ago

2026-09-30

PUBLISHED

1h ago

2026-09-30

RELEVANCE

7/ 10

AUTHOR

tan_stack