Skip to content
Read the original: Lovable Blog· Talia Moyal·Published AI score47/100

Lovable Discloses TanStack Start Vulnerability CVE-2026-102989 and Protects Hosted Apps

Original titleA vulnerability in TanStack Start: what we found and what we did to protect your apps

AISummary

Lovable's security team found a vulnerability (CVE-2026-102989) in TanStack Start, which allows attackers to run unwanted JavaScript in visitors' browsers via crafted links.

Lovable reported it to TanStack and deployed firewall protections for hosted apps while a fix was prepared, and affected projects will be automatically updated on their next change or via the Security page.

Lovable says it found no evidence of exploitation in reviewed logs, and apps hosted elsewhere must apply the upstream update themselves.

Read the original lovable.dev

Source: Lovable Blog · lovable.dev