TanStack

TanStack Start security update: CVE-2026-102989

by Tanner Linsley on Sep 30, 2026.

We've released a fix for CVE-2026-102989, a critical reflected cross-site scripting (XSS) vulnerability in TanStack Start's server-function response handling. The patched packages are available on npm now, and we recommend upgrading and redeploying affected applications immediately.

An unauthenticated attacker could craft a server-function URL that returns attacker-controlled HTML from an affected application's origin. If a user opens that link, the attacker's JavaScript could run with that user's access to the application. The fix restricts client-supplied input and validates responses at the server boundary.

Upgrade to a patched version

Versions from 1.143.12 up to, but excluding, the corresponding patched version below are affected.

PackageFirst patched version
@tanstack/react-start1.168.60
@tanstack/solid-start1.168.57
@tanstack/vue-start1.168.56
@tanstack/start-server-core1.169.39

Update your Start dependencies and lockfile, confirm that the resolved @tanstack/start-server-core version is 1.169.39 or later, then rebuild and redeploy. Updating a local installation alone doesn't patch an already deployed application. Edge mitigations can help while upgrading, but they aren't a replacement for the fix.

We privately briefed hosting providers, distributors, and affected partners ahead of this release so they could prepare. Thank you to Lovable for helping us discover the issue and working with us to fix it.

See the GitHub security advisory for the affected ranges, severity, and mitigation details.