Lovable News 09/30/2026 AI Rating: Medium

Lovable Discloses and Patches a TanStack Start Vulnerability Across Hosted Apps

#Lovable#Security#TanStack Start#Vulnerability#CVE

Lovable published a security disclosure on September 30, 2026, detailing a vulnerability its security team found in the TanStack Start framework, CVE-2026-102989, and the steps it took to protect apps built on its platform while a permanent fix was prepared upstream.

Details

  • The vulnerability: a specially crafted link could trigger malicious JavaScript execution in a visitor’s browser on apps using affected TanStack Start server functionality, potentially letting an attacker access information available to that visitor or act with their permissions
  • Not automatic: using TanStack Start alone did not make an app vulnerable; exploitation required both the affected server functionality and a visitor actually clicking a malicious link
  • Timeline: Lovable’s security researcher identified the issue on September 14, 2026, and reported it to TanStack’s maintainers the same day
  • Immediate mitigation: Lovable deployed firewall rules to block exploitation attempts on hosted apps right away, then refined those rules over time to improve coverage while limiting false positives
  • No evidence of exploitation: Lovable says a review of logs turned up no sign that the vulnerability was actually exploited against hosted apps
  • Remediation path: hosted apps get the dependency upgrade automatically on a user’s next edit, or users can trigger it manually at no cost from the app’s Security page; apps hosted outside Lovable need to apply the upstream TanStack Start update themselves

What happened next

The disclosure is a rare moment of public transparency from an AI app-building platform about a framework-level security issue affecting its hosted customer apps, and it doubles as a reminder that vibe-coded apps inherit the security posture of their underlying frameworks. Because Lovable found and reported the issue itself, shipped a network-level mitigation before a patch existed, and says its logs show no actual exploitation, the incident reads as a successful catch rather than a breach — but it also underscores that anyone running a TanStack Start app outside Lovable’s hosting needs to update independently, since Lovable’s firewall rules only protect apps it hosts.