vulns.co
/
GKData.io MCP

TanStack · 2 min read

TanStack Start: preserve server-owned response authority through errors

TanStack's CVE-2026-102989 advisory describes client request data entering internal middleware state. Failure handling could retain an untrusted result that response processing then accepted as an HTTP response. The maintainer confirms reflected same-origin XSS and classifies it as CWE-79. The boundary failure is client data acquiring server response authority, including on an error path.

Open the reference Maintainer AdvisoryReviewed 2026-10-04

How to use this reference

The announced fix narrows accepted client input and checks server responses. Update dependencies and the lockfile, verify resolved @tanstack/start-server-core is at least 1.169.39, then rebuild and redeploy; local upgrades alone leave deployed code unchanged. Editorial lesson: keep internal state separate from public input, and preserve response provenance through exceptions. Supplementary edge controls do not replace the package fix.

Before reading

  • HTTP response handling, browser same-origin authority and reflected XSS concepts
  • Middleware error handling and dependency-resolution basics

Context and limits

  • Exposure requires an affected deployed server function and a visitor opening the supplied link. The described script authority is limited to that visitor's same-origin access; neither source provides a public demonstration transcript or evidence of production compromise or actual theft.
  • Both sources give affected ranges beginning at 1.143.12, inclusive, and ending before each package's first patched version: @tanstack/react-start 1.168.60; @tanstack/solid-start 1.168.57; @tanstack/vue-start 1.168.56; @tanstack/start-server-core 1.169.39.
  • The September 30 announcement states that patched packages were available by then; it does not establish a separate resource edition or each package's exact release date.
  • GitHub identifies tannerlinsley as advisory publisher, not an explicit author byline; authors therefore remains empty. The supporting blog names Tanner Linsley. The advisory credits Lovable for helping discover and report the issue.
  • This concerns reflected response authority, distinct from the library's Next.js Re:CACHE metadata and shared-cache case. No individual bounty amount is established. This educational record grants no testing authorization.

Sources and provenance

  1. Unauthenticated reflected XSS in TanStack Start server-function responses TanStack · reviewed 2026-10-04
  2. TanStack Start security update: CVE-2026-102989 TanStack · reviewed 2026-10-04

Record reviewed 2026-10-04. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software