Security Update: Cross-site scripting in TanStack Start

September 30, 2026

The TanStack team has disclosed a critical cross-site scripting (XSS) vulnerability in TanStack Start. A crafted URL can cause an affected app to return attacker-controlled HTML from its own origin, which may run attacker-supplied JavaScript in a visitor’s browser. Here’s what Netlify customers need to know.

Vulnerabilities

GHSA-qx66-fv34-fjm8 (CVE-2026-102989): Unauthenticated reflected XSS in server-function responses.

PackageAffected versionsFixed in
@tanstack/react-start>= 1.143.12, < 1.168.601.168.60
@tanstack/solid-start>= 1.143.12, < 1.168.571.168.57
@tanstack/vue-start>= 1.143.12, < 1.168.561.168.56
@tanstack/start-server-core>= 1.143.12, < 1.169.391.169.39

Impact on Netlify

This is a client-side cross-site scripting (XSS) vulnerability in TanStack Start’s server-function response handling. Because the malicious response is returned from the app’s own origin, an attacker who gets a victim to open a crafted link can run JavaScript in that visitor’s session — for example, to read their data or act as them on the site. All applications on an affected version should upgrade.

What should I do?

We strongly recommend upgrading as soon as possible to the patched releases:

  • @tanstack/react-start 1.168.60 or later
  • @tanstack/solid-start 1.168.57 or later
  • @tanstack/vue-start 1.168.56 or later
  • @tanstack/start-server-core 1.169.39 or later

Not sure if you’re affected?

Open your project in Agent Runners in ask mode and try this prompt:

Does this project use TanStack Start? If so, which versions of `@tanstack/react-start`, `@tanstack/solid-start`, `@tanstack/vue-start`, and `@tanstack/start-server-core` are resolved in the lockfile? Is the resolved `@tanstack/start-server-core` version 1.169.39 or later? If not, what do I need to change to upgrade? (Advisory: GHSA-qx66-fv34-fjm8)

Ask mode answers without changing your code. If an upgrade is needed, switch to Build mode to make the change, preview, and redeploy.

Deploy previews and branch deploys

Note that any publicly available deploy previews and branch deploys may remain vulnerable until they are automatically deleted. Consider deleting these deploys manually.

Resources