Skip to main content
Framework flaw patched

Lovable Addresses TanStack Start Vulnerability

Lovable's security team discovered a critical vulnerability in TanStack Start that could allow attackers to execute malicious code through specially crafted links. The company has already deployed firewall protections and integrated patches into its platform, automatically updating affected projects without user intervention.
A translucent shield icon glows against a gradient background of blue, pink, and orange hues.
A translucent shield icon glows against a gradient background of blue, pink, and orange hues.

Lovable's security team discovered a vulnerability in TanStack Start, the framework powering Lovable apps, and has deployed firewall protections while a fix is prepared. Affected projects will be automatically updated the next time you make a change in Lovable, or you can apply the fix immediately through your project's Security page at no additional cost.

Not all Lovable projects were affected. If yours was, you'll receive an email notification.

What was found

On September 14, 2026, a security researcher identified the vulnerability while examining software libraries used by Lovable apps. The vulnerability could allow an attacker to use a specially crafted link to execute unwanted JavaScript in a visitor's browser, potentially accessing information available to that visitor or performing actions with their permissions.

The attack required both affected server functionality and a visitor opening the malicious link. Using TanStack Start alone did not make every app exploitable. Lovable has found no evidence of exploitation in its logs.

Immediate protections

Lovable submitted a vulnerability report to TanStack on September 14 and immediately began enforcing firewall rules designed to block exploitation attempts in hosted apps. Because apps run on Lovable's platform, the company could deploy these protections without requiring users to take action or change settings. Lovable also coordinated disclosure with TanStack's maintainers to give them time to address the issue before technical details became public.

Getting updated

Lovable has integrated the TanStack Start patch into its standard workflow. The next time you make a change to an affected project, the coding agent automatically upgrades to the patched version without requiring manual intervention. You can also apply the fix immediately through your project's Security page at no cost. New projects use the patched version from the start, and firewall protections remain active while existing projects are updated.

For apps hosted elsewhere

If you host your app outside Lovable, the platform's firewall protections do not cover that deployment. You'll need to apply the upstream security update and redeploy through your hosting provider.

For questions, contact Lovable Support.

Model Price Where to buy As-of date
Free $0/month Lovable website Sep. 2026
Pro From $25/month Lovable website Sep. 2026
Business From $50/month Lovable website Sep. 2026
Prices subject to change.

Jennifer friend

The greatest technological advancement is our ability to be truly present where life happens – Jenny F.