The TanStack Start server-function XSS
- CVE-2026-102989
- CVSS 9.3
- Fresh · still developing
- No exploitation reported
A link to your own app's server-function endpoint could make your server answer with HTML an attacker chose, and run it as whoever clicked. Disclosed on 30 September 2026. This is how it worked, layer by layer, and what to do now.