# Security Update: Cross-site scripting in TanStack Start

By Steven Van · 2026-09-30

Netlify urges anyone running TanStack Start to upgrade to patched releases, and to delete old deploy previews and branch deploys that may stay vulnerable.

Netlify has published guidance on a critical cross-site scripting (XSS) vulnerability in [TanStack Start](<https://www.netlify.com/changelog/2026-09-30-tanstack-start-security-vulnerability/>), disclosed by the TanStack team. A crafted URL can make an affected app return attacker-controlled HTML from its own origin, which may run attacker-supplied JavaScript in a visitor's browser. The flaw is an unauthenticated reflected XSS in server-function responses (GHSA-qx66-fv34-fjm8, CVE-2026-102989).

Because the response comes from the app's own origin, an attacker who gets a victim to open a crafted link can run JavaScript in that visitor's session, for example to read their data or act as them on the site. Netlify says all applications on an affected version should upgrade as soon as possible. Affected versions start at 1.143.12 in each package, and the fixed releases are:

- @tanstack/react-start 1.168.60 or later

- @tanstack/solid-start 1.168.57 or later

- @tanstack/vue-start 1.168.56 or later

- @tanstack/start-server-core 1.169.39 or later

To check a project, Netlify suggests opening it in **Agent Runners** in ask mode and prompting it to report which of these packages the lockfile resolves, and whether @tanstack/start-server-core is at 1.169.39 or later. Ask mode answers without changing code. If an upgrade is needed, Build mode can make the change, preview it and redeploy.

Publicly available deploy previews and branch deploys may stay vulnerable until they are automatically deleted. Netlify suggests deleting them manually.

![Netlify](<https://www.google.com/s2/favicons?domain=netlify.com&sz=128>)

Netlify

Lightning-fast web platform for deploying, hosting, and scaling modern sites — one-click deploys from Git or any modern AI builder.

[View Netlify →](<https://creatorstoolbox.com/tools/netlify>)

[Read the original announcement →](<https://www.netlify.com/changelog/2026-09-30-tanstack-start-security-vulnerability/>)

[Read Security Update: Cross-site scripting in TanStack Start on Creators Toolbox](<https://creatorstoolbox.com/blog/netlify-security-update-cross-site-scripting-in-tanstack-start>)

---
Canonical source: https://creatorstoolbox.com/blog/netlify-security-update-cross-site-scripting-in-tanstack-start
