
TanStack Start's security fix for CVE-2026-102989 is now available. Please upgrade and redeploy affected apps. Thanks to Lovable for helping us discover and fix it. https://tanstack.com/blog/tanstack-start-security-update-cve-2026-102989
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE

TanStack Start's security fix for CVE-2026-102989 is now available. Please upgrade and redeploy affected apps. Thanks to Lovable for helping us discover and fix it. https://tanstack.com/blog/tanstack-start-security-update-cve-2026-102989

TanStack Start に critical の reflected XSS(CVE-2026-102989)が出た。server function のレスポンス処理まわり。認証なしの攻撃者が、アプリと同じ origin から攻撃者の HTML を返す URL を作れて、そのリンクを開いたユーザーの権限で JavaScript が動く可能性がある、としている。 影響は 1.143.12 以上〜パッチ未満。上げ先は `@tanstack/react-start` 1.168.60、`@tanstack/solid-start` 1.168.57、`@tanstack/vue-start` 1.168.56。実体は `@tanstack/start-server-core` 1.169.39 以降が入ること。lockfile を直して rebuild して redeploy しないと、手元だけ上げても本番は直らない。ホスト側の edge 緩和は助けになるが、パッチの代わりにはならない、とのこと。 Start を本番で動かしている人は優先して当てたい。 #TanStack #Security https://tanstack.com/blog/tanstack-start-security-update-cve-2026-102989