Lovable Discloses TanStack Start Vulnerability CVE-2026-102989 and Protects Hosted Apps
Original titleA vulnerability in TanStack Start: what we found and what we did to protect your apps
AISummary
Lovable's security team found a vulnerability (CVE-2026-102989) in TanStack Start, which allows attackers to run unwanted JavaScript in visitors' browsers via crafted links.
Lovable reported it to TanStack and deployed firewall protections for hosted apps while a fix was prepared, and affected projects will be automatically updated on their next change or via the Security page.
Lovable says it found no evidence of exploitation in reviewed logs, and apps hosted elsewhere must apply the upstream update themselves.
Source: Lovable Blog · lovable.dev