TanStack Start CVE-2026-102989 (CVSS 9.3): critical reflected XSS via server-function responses — patch react-start 1.168.60+
TanStack (Tanner Linsley; blog and GHSA-qx66-fv34-fjm8, 30 September 2026; HN amplified 1 Oct) discloses CVE-2026-102989, a critical reflected cross-site scripting flaw in TanStack Start server-function response handling. The server-function transport can pass request payload fields into internal middleware state instead of limiting them to public input fields; an unauthenticated attacker can craft a server-function URL that returns attacker-controlled HTML from the application's origin. CVSS 3.1 9.3 Critical (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N). Affected: published @tanstack/start-server-core, react-start, solid-start, and vue-start from 1.143.12 up to (excluding) patched versions. Fixed: start-server-core 1.169.39; react-start 1.168.60; solid-start 1.168.57; vue-start 1.168.56. Redeploy required after dependency bump. Temporary mitigations: edge/WAF rules on /_serverFn/* (e.g. require x-tsr-serverFn: true; block document navigations); restrictive CSP on server-function responses. Distinct from desk crowdsec-tanstack-source-20260917 (May 2026 npm supply-chain/source exposure). Primary: TanStack blog / GHSA.
- Product
- TanStack Start (@tanstack/react-start, solid-start, vue-start, start-server-core)
- Versions
- Affected: packages from 1.143.12 up to (but excluding) patched versions. Fixed: @tanstack/start-server-core 1.169.39+; @tanstack/react-start 1.168.60+; @tanstack/solid-start 1.168.57+; @tanstack/vue-start 1.168.56+.
- CVSS
- (CVSS 3.1 Critical; GHSA)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N - Exploited in Australia?
- unknown
- Patch to
- Upgrade Start dependencies and lockfile so resolved @tanstack/start-server-core is 1.169.39+, then rebuild and redeploy (local update alone does not patch production). Until then: WAF/edge rules on server-function path (usually /_serverFn/*); require x-tsr-serverFn: true; block browser document navigations to that path; tighten CSP on those responses.
Primary: TanStack Blog — Start security update CVE-2026-102989 (30 Sep 2026) · Vendor: GitHub Advisory GHSA-qx66-fv34-fjm8 — CVE-2026-102989 · CVE: CVE-2026-102989
