Security Update: Cross-site scripting in TanStack Start
Update3 days agoUnverifiedAdded Oct 2, 2026
The TanStack team has disclosed a critical cross-site scripting (XSS) vulnerability in TanStack Start. A crafted URL can cause an affected app to return attacker-controlled HTML from its own origin, which may run attacker-supplied JavaScript in a visitor's browser. Here's what Netlify customers need to know.
More Netlify releases
Every Netlify release| Date | Release | Type |
|---|---|---|
| Sep 303 days ago | Update | Update |
| Sep 303 days ago | Trust Center is now in the Netlify Dashboard unverified Update | Update |
| Sep 294 days ago | Rich link previews for Agent Runners sites unverified Preview | Preview |
| Sep 294 days ago | Update | Update |
| Sep 285 days ago | Preview | Preview |
| Sep 285 days ago | Update | Update |
| Sep 249 days ago | New project activity feed unverified Preview | Preview |
| Sep 2211 days ago | Update | Update |
Also shipped on Sep 30, 2026
Netlify in September 2026| Date | Company | Release | Product | Type |
|---|---|---|---|---|
| Sep 303 days ago | New Relic | Preview | ||
| Sep 303 days ago | New Relic | Preview | ||
| Sep 303 days ago | Astro | Preview | ||
| Sep 303 days ago | The Astro IDE is generally available unverified | Astro | GA | |
| Sep 303 days ago | Cloudflare developer platform | Beta | ||
| Sep 303 days ago | Cloudflare developer platform | Beta |