Our security team discovered a vulnerability (CVE-2026-102989) in TanStack Start, a framework used by Lovable apps. We reported it to the maintainers and put firewall protections in place for apps hosted on Lovable while they prepared a fix.
You also don’t need to take any action. Lovable automatically updates affected projects the next time you make a change. If you want to apply the update without making another change to your app, you can do so for free through your project’s Security page.
Not all Lovable projects were impacted. If your project was affected, we will reach out via email.
Here’s what we found, how we responded, and what it means for your app.
What we found
On September 14, 2026, a security researcher on our security team identified the vulnerability while examining software libraries powering Lovable apps. His job is to think like an attacker: actively trying to break the software behind your app so we can find weaknesses and address them. This discovery came from that proactive work.
The vulnerability could allow an attacker to use a specially crafted link to make an affected app run unwanted JavaScript in a visitor’s browser. That code could access information available to the visitor or perform actions with their permissions inside the affected app.
The attack we identified required both affected server functionality and a visitor opening the malicious link. Using TanStack Start did not, by itself, make every app exploitable.
We have not found evidence of exploitation in the logs we have reviewed.
Protecting apps while a fix was developed
We submitted a vulnerability report to TanStack on September 14. Following this, we began enforcing firewall rules designed to block attempts to exploit the issue in hosted apps.
We continued testing and refining those rules to improve coverage and avoid blocking legitimate requests. The firewall provided a mitigation while the upstream fix was being prepared.
Because your app runs on Lovable, we could put these protections in place without waiting for you to read a security alert or change a setting. One patch from our team could reach hosted apps across the platform. We also coordinated disclosure with TanStack’s maintainers to give them time to address the issue before its technical details became public.
Getting the fix into your project
We’ve built the update into the way you already work on Lovable. The next time you make a change to an affected project, the coding agent automatically upgrades TanStack Start to the patched version. You don’t need to identify the package or work out how to update it yourself.
If you want to apply the fix before continuing to build, you can do that through your project’s Security page at no credit cost.
New projects use the patched version from the start.
Our firewall protections remain in place while existing projects are updated.
Security work built into the platform
Our security testing includes the third-party software Lovable depends on. When we find a vulnerability, our work extends from reporting it to the maintainers through to protecting the apps that use it.
For this issue, that means proactive research that uncovered the vulnerability, firewall protections deployed before the official fix was available, and an update built into your next editing session. Our security scanner also gives you a way to find and fix the affected dependency without making other changes.
This research benefits more than the apps hosted on Lovable. By finding the vulnerability and reporting it to TanStack’s maintainers, our team helped bring a fix to the wider community using the framework.
You shouldn’t need to become a security expert to keep building. Hosting on Lovable means our team can take on more of the work behind keeping your app secure, while you focus on what you’re creating and the people using it.
What you need to do
For apps hosted on Lovable, the firewall protections are already in place without any action from you. To update the affected software in your project, make your next change in Lovable or apply the fix through the Security page for free.
If you host your app elsewhere, Lovable’s hosting protections do not cover that deployment. Apply the upstream security update and redeploy the app through your hosting setup.
Customers with questions about this update can contact Lovable Support.



