Skip to content

Security Update: Cross-site scripting in TanStack Start

Update3 days agoUnverifiedAdded Oct 2, 2026

The TanStack team has disclosed a critical cross-site scripting (XSS) vulnerability in TanStack Start. A crafted URL can cause an affected app to return attacker-controlled HTML from its own origin, which may run attacker-supplied JavaScript in a visitor's browser. Here's what Netlify customers need to know.

Topics: AI agents, Security

Netlify's release notes

More Netlify releases

Every Netlify release
DateRelease
Sep 303 days ago
Update
Sep 303 days ago
Update
Sep 294 days ago
Preview
Sep 294 days ago
Update
Sep 285 days ago
Preview
Sep 285 days ago
Update
Sep 249 days ago
Preview
Sep 2211 days ago
Update

Also shipped on Sep 30, 2026

Netlify in September 2026

New releases by email

Tuesday mornings: the week's data, AI and developer-tools releases, only in weeks when something shipped.

Double opt-in. Unsubscribe any time.