Plate 63
TanStack Start XSS: Patch CVE-2026-102989 Now
TanStack Start CVE-2026-102989: patched versions, lockfile checks, and redeploy steps from the official advisory.
Aditya Challa4 min read
On 30 September 2026, TanStack published a critical security update for TanStack Start: CVE-2026-102989, a reflected cross-site scripting (XSS) issue in server-function response handling. If you ship Start in production, treat this as a patch-and-redeploy day—not a “read later” advisory.
Related posts on ShopperCove:
- Next.js 16 App Router Production Checklist (2026)
- Build an AI Chat UI with Next.js & shadcn (2026)
- Lily in CI: Fuzz-Based Backdoor Detection
- Cosign + SBOM in CI
- After xz: Practical Supply-Chain Checklist
- Setting up AI Coworkers with OpenBot
- OpenTelemetry + Prometheus + Grafana
- Grow Site Traffic in the AI Search Era (2026)
What went wrong (plain English)
An unauthenticated attacker could craft a server-function URL that returns attacker-controlled HTML from your application’s origin. If a user opens that link, the attacker’s JavaScript can run with that user’s access to your app.
TanStack’s fix restricts client-supplied input and validates responses at the server boundary. Hosting-edge rules may buy time; they are not a substitute for upgrading and redeploying.
Primary sources (read these, do not rely on secondary summaries alone):
- TanStack blog advisory
- Appwrite’s operator notes for Sites deployments: what to do on Appwrite
ShopperCove has not reproduced the exploit. This post is an operator checklist from public vendor advisories only—no PoC, no attack steps.
Who is affected
TanStack lists versions from 1.143.12 up to (but excluding) each patched line below as affected. Confirm what your lockfile resolves—not just what package.json asks for.
| Package | First patched version |
|---|---|
@tanstack/react-start | 1.168.60 |
@tanstack/solid-start | 1.168.57 |
@tanstack/vue-start | 1.168.56 |
@tanstack/start-server-core | 1.169.39 |
After upgrade, confirm @tanstack/start-server-core resolves to 1.169.39 or later.
Patch checklist (do this today)
- Inventory — search the monorepo for
@tanstack/react-start,@tanstack/solid-start,@tanstack/vue-start, and@tanstack/start-server-core. - Upgrade — bump to the patched versions for your framework line; refresh the lockfile.
- Verify resolve — open the lockfile (or
npm ls @tanstack/start-server-core) and confirm ≥ 1.169.39. - Rebuild + redeploy — a local
node_modulesbump without a new production deploy leaves the live app vulnerable. - Smoke the app — login, one write path, and any server-function heavy screens. If a host added temporary WAF rules (for example Appwrite’s edge header checks), expect some server-function calls to fail until the patched build is live—then retest.
- Record — note the advisory id (CVE-2026-102989), the deploy SHA, and who signed off. Pair this habit with your usual supply-chain hygiene (after xz checklist, Cosign + SBOM).
Edge mitigations vs the real fix
Some hosts block known request patterns (for example requiring TanStack’s client header on server-function calls). That reduces exposure while you ship. TanStack is explicit: edge mitigations help while upgrading; they are not a replacement for the fix. Your site is only fixed when the patched packages are what production actually runs.
Adjacent Next.js note (different CVE)
If you also run Next.js 16.2–16.3.5 with Node.js ImageResponse from next/og and pass user-controlled values into SVG markup, review Vercel’s separate September 2026 update (patched at Next.js 16.3.6 for that RCE path). It is unrelated to TanStack Start—do not conflate the two—but many frontend shops run both stacks. See our Next.js 16 App Router checklist for production hygiene after you patch.
Printable operator checklist
- Confirm Start packages in the lockfile
- Upgrade to the patched versions in the table above
- Assert
start-server-core≥ 1.169.39 - Redeploy production (not just local install)
- Smoke auth + server-function paths
- File the CVE + deploy SHA in your change log
- Keep CI signing/SBOM habits for the next advisory
No affiliate links on this post—security patching is not a product pitch. Ship the upgrade, then get back to product work
Lab evidence
What I found running this
Trend + US security case (vendor advisory summary only). No exploit PoC. No invented lab numbers. Drafted 1 Oct 2026 IST routine run. Affiliates: 0. Operator checklist only from TanStack advisory CVE-2026-102989 and Appwrite notes. No exploit reproduction on ShopperCove. Affiliates: 0 (security patch post).
Related links
Plate 45
Tailwind CSS v4 Migration Checklist (2026)
Practical Tailwind CSS v4 migration checklist for Next.js/React teams: @theme tokens, upgrade CLI pitfalls, and what to verify before production.
1 Oct 2026
Plate 53
Next.js 16.3 for AI Coding Agents (2026)
Practical Next.js 16.3 guide for AI coding agents: AGENTS.md, first-party Skills, agent-browser, Instant Insights, DevTools MCP.
1 Oct 2026
Plate 59
Build an AI Chat UI with Next.js & shadcn (2026)
Build an AI Chat UI with Next.js & shadcn (2026)
1 Oct 2026