# Lovable — A vulnerability in TanStack Start: what we found and what we did to protect your apps

- Company: Lovable (lovable.dev)
- Announced: 2026-09-30T15:45:00+00:00
- Category: safety-policy-update
- Coverage: not counted
- Announcement: yes
- Group: announcements
- Source: https://lovable.dev/blog/how-lovable-protects-your-app-from-a-tanstack-start-vulnerability
- Record: https://forck.live/items/15417-a-vulnerability-in-tanstack-start-what-we-found-and-what-we-did-to-protect
- Subject: Lovable / AI app builder

Lovable's security team discovered a vulnerability in TanStack Start, a framework used by Lovable apps, and reported it to maintainers. Firewall protections were deployed for hosted apps, and affected projects are automatically updated when users make changes. No evidence of exploitation was found.

## Evidence

Verbatim from https://lovable.dev/blog/how-lovable-protects-your-app-from-a-tanstack-start-vulnerability:

> Our security team discovered a vulnerability in TanStack Start, a framework used by Lovable apps. We reported it to the maintainers and put firewall protections in place for apps hosted on Lovable while they prepared a fix.

---

Record: https://forck.live/items/15417-a-vulnerability-in-tanstack-start-what-we-found-and-what-we-did-to-protect
Catalogue: https://forck.live/llms.txt
Current issue: https://forck.live/feed.md
