How to use this reference
The announced fix narrows accepted client input and checks server responses. Update dependencies and the lockfile, verify resolved @tanstack/start-server-core is at least 1.169.39, then rebuild and redeploy; local upgrades alone leave deployed code unchanged. Editorial lesson: keep internal state separate from public input, and preserve response provenance through exceptions. Supplementary edge controls do not replace the package fix.
Before reading
- HTTP response handling, browser same-origin authority and reflected XSS concepts
- Middleware error handling and dependency-resolution basics
Context and limits
- Exposure requires an affected deployed server function and a visitor opening the supplied link. The described script authority is limited to that visitor's same-origin access; neither source provides a public demonstration transcript or evidence of production compromise or actual theft.
- Both sources give affected ranges beginning at 1.143.12, inclusive, and ending before each package's first patched version: @tanstack/react-start 1.168.60; @tanstack/solid-start 1.168.57; @tanstack/vue-start 1.168.56; @tanstack/start-server-core 1.169.39.
- The September 30 announcement states that patched packages were available by then; it does not establish a separate resource edition or each package's exact release date.
- GitHub identifies tannerlinsley as advisory publisher, not an explicit author byline; authors therefore remains empty. The supporting blog names Tanner Linsley. The advisory credits Lovable for helping discover and report the issue.
- This concerns reflected response authority, distinct from the library's Next.js Re:CACHE metadata and shared-cache case. No individual bounty amount is established. This educational record grants no testing authorization.
Sources and provenance
- Unauthenticated reflected XSS in TanStack Start server-function responses TanStack · reviewed 2026-10-04
- TanStack Start security update: CVE-2026-102989 TanStack · reviewed 2026-10-04
Record reviewed 2026-10-04. Snapshot d5550c789111. Open the complete JSON contract.