Critical TanStack Start XSS (CVSS 9.3) hits AI-built apps; patch and redeploy
Lovable found an unauthenticated reflected XSS (GHSA-qx66-fv34-fjm8) in TanStack Start server functions: a crafted link runs attacker JS on your app's origin with the visitor's access, affecting versions from 1.143.12. Upgrade to @tanstack/react-start 1.168.60+ (or start-server-core 1.169.39+) and redeploy, since a local update alone doesn't patch a live app.