Security Update: Cross-site scripting in TanStack Start
September 30, 2026
The TanStack team has disclosed a critical cross-site scripting (XSS) vulnerability in TanStack Start. A crafted URL can cause an affected app to return attacker-controlled HTML from its own origin, which may run attacker-supplied JavaScript in a visitor’s browser. Here’s what Netlify customers need to know.
Vulnerabilities
GHSA-qx66-fv34-fjm8 (CVE-2026-102989): Unauthenticated reflected XSS in server-function responses.
| Package | Affected versions | Fixed in |
|---|---|---|
@tanstack/react-start | >= 1.143.12, < 1.168.60 | 1.168.60 |
@tanstack/solid-start | >= 1.143.12, < 1.168.57 | 1.168.57 |
@tanstack/vue-start | >= 1.143.12, < 1.168.56 | 1.168.56 |
@tanstack/start-server-core | >= 1.143.12, < 1.169.39 | 1.169.39 |
Impact on Netlify
This is a client-side cross-site scripting (XSS) vulnerability in TanStack Start’s server-function response handling. Because the malicious response is returned from the app’s own origin, an attacker who gets a victim to open a crafted link can run JavaScript in that visitor’s session — for example, to read their data or act as them on the site. All applications on an affected version should upgrade.
What should I do?
We strongly recommend upgrading as soon as possible to the patched releases:
@tanstack/react-start1.168.60 or later@tanstack/solid-start1.168.57 or later@tanstack/vue-start1.168.56 or later@tanstack/start-server-core1.169.39 or later
Not sure if you’re affected?
Open your project in Agent Runners in ask mode and try this prompt:
Does this project use TanStack Start? If so, which versions of `@tanstack/react-start`, `@tanstack/solid-start`, `@tanstack/vue-start`, and `@tanstack/start-server-core` are resolved in the lockfile? Is the resolved `@tanstack/start-server-core` version 1.169.39 or later? If not, what do I need to change to upgrade? (Advisory: GHSA-qx66-fv34-fjm8)
Ask mode answers without changing your code. If an upgrade is needed, switch to Build mode to make the change, preview, and redeploy.
Deploy previews and branch deploys
Note that any publicly available deploy previews and branch deploys may remain vulnerable until they are automatically deleted. Consider deleting these deploys manually.