ShopperCove
Menu
All writingBlogTopicsCategoriesAboutRSS
Blog
Categories
Observability & SRE62All categories
About

Plate 63

  1. Blog

TanStack Start XSS: Patch CVE-2026-102989 Now

TanStack Start CVE-2026-102989: patched versions, lockfile checks, and redeploy steps from the official advisory.

Aditya Challa·1 October 2026·4 min read

News
On this page
  1. What went wrong (plain English)
  2. Who is affected
  3. Patch checklist (do this today)
  4. Edge mitigations vs the real fix
  5. Adjacent Next.js note (different CVE)
  6. Printable operator checklist 

On 30 September 2026, TanStack published a critical security update for TanStack Start: CVE-2026-102989, a reflected cross-site scripting (XSS) issue in server-function response handling. If you ship Start in production, treat this as a patch-and-redeploy day—not a “read later” advisory.

Related posts on ShopperCove:

  • Next.js 16 App Router Production Checklist (2026)
  • Build an AI Chat UI with Next.js & shadcn (2026)
  • Lily in CI: Fuzz-Based Backdoor Detection
  • Cosign + SBOM in CI
  • After xz: Practical Supply-Chain Checklist
  • Setting up AI Coworkers with OpenBot
  • OpenTelemetry + Prometheus + Grafana
  • Grow Site Traffic in the AI Search Era (2026)

What went wrong (plain English)

An unauthenticated attacker could craft a server-function URL that returns attacker-controlled HTML from your application’s origin. If a user opens that link, the attacker’s JavaScript can run with that user’s access to your app.

TanStack’s fix restricts client-supplied input and validates responses at the server boundary. Hosting-edge rules may buy time; they are not a substitute for upgrading and redeploying.

Primary sources (read these, do not rely on secondary summaries alone):

  • TanStack blog advisory
  • Appwrite’s operator notes for Sites deployments: what to do on Appwrite

ShopperCove has not reproduced the exploit. This post is an operator checklist from public vendor advisories only—no PoC, no attack steps.

Who is affected

TanStack lists versions from 1.143.12 up to (but excluding) each patched line below as affected. Confirm what your lockfile resolves—not just what package.json asks for.

PackageFirst patched version
@tanstack/react-start1.168.60
@tanstack/solid-start1.168.57
@tanstack/vue-start1.168.56
@tanstack/start-server-core1.169.39

After upgrade, confirm @tanstack/start-server-core resolves to 1.169.39 or later.

Patch checklist (do this today)

  1. Inventory — search the monorepo for @tanstack/react-start, @tanstack/solid-start, @tanstack/vue-start, and @tanstack/start-server-core.
  2. Upgrade — bump to the patched versions for your framework line; refresh the lockfile.
  3. Verify resolve — open the lockfile (or npm ls @tanstack/start-server-core) and confirm ≥ 1.169.39.
  4. Rebuild + redeploy — a local node_modules bump without a new production deploy leaves the live app vulnerable.
  5. Smoke the app — login, one write path, and any server-function heavy screens. If a host added temporary WAF rules (for example Appwrite’s edge header checks), expect some server-function calls to fail until the patched build is live—then retest.
  6. Record — note the advisory id (CVE-2026-102989), the deploy SHA, and who signed off. Pair this habit with your usual supply-chain hygiene (after xz checklist, Cosign + SBOM).

Edge mitigations vs the real fix

Some hosts block known request patterns (for example requiring TanStack’s client header on server-function calls). That reduces exposure while you ship. TanStack is explicit: edge mitigations help while upgrading; they are not a replacement for the fix. Your site is only fixed when the patched packages are what production actually runs.

Adjacent Next.js note (different CVE)

If you also run Next.js 16.2–16.3.5 with Node.js ImageResponse from next/og and pass user-controlled values into SVG markup, review Vercel’s separate September 2026 update (patched at Next.js 16.3.6 for that RCE path). It is unrelated to TanStack Start—do not conflate the two—but many frontend shops run both stacks. See our Next.js 16 App Router checklist for production hygiene after you patch.

Printable operator checklist

  1. Confirm Start packages in the lockfile
  2. Upgrade to the patched versions in the table above
  3. Assert start-server-core ≥ 1.169.39
  4. Redeploy production (not just local install)
  5. Smoke auth + server-function paths
  6. File the CVE + deploy SHA in your change log
  7. Keep CI signing/SBOM habits for the next advisory

No affiliate links on this post—security patching is not a product pitch. Ship the upgrade, then get back to product work

tanstack startcve-2026-102989xssserver functionsreact-startsecurity patchfrontend security2026

Lab evidence

What I found running this

Trend + US security case (vendor advisory summary only). No exploit PoC. No invented lab numbers. Drafted 1 Oct 2026 IST routine run. Affiliates: 0. Operator checklist only from TanStack advisory CVE-2026-102989 and Appwrite notes. No exploit reproduction on ShopperCove. Affiliates: 0 (security patch post).

Notes when a lab post goes up

Occasional email for new hands-on reviews. No sequence and no sponsors.

Related links

  • Plate 45

    Tailwind CSS v4 Migration Checklist (2026)

    Practical Tailwind CSS v4 migration checklist for Next.js/React teams: @theme tokens, upgrade CLI pitfalls, and what to verify before production.

    1 Oct 2026

  • Plate 53

    Next.js 16.3 for AI Coding Agents (2026)

    Practical Next.js 16.3 guide for AI coding agents: AGENTS.md, first-party Skills, agent-browser, Instant Insights, DevTools MCP.

    1 Oct 2026

  • Plate 59

    Build an AI Chat UI with Next.js & shadcn (2026)

    Build an AI Chat UI with Next.js & shadcn (2026)

    1 Oct 2026

On this page

  1. What went wrong (plain English)
  2. Who is affected
  3. Patch checklist (do this today)
  4. Edge mitigations vs the real fix
  5. Adjacent Next.js note (different CVE)
  6. Printable operator checklist 
All writingBlogCategoriesTopicsAboutPrivacyRSS

© 2026 ShopperCove