Executive brief
A vulnerability in TanStack Start's server core could allow a specially crafted request to trigger the execution of a different server function than the one intended. While this does not bypass security checks like authentication or input validation, it could lead to unexpected side effects or inconsistent audit logs. This issue primarily affects applications using the Seroval library for data serialization.
Technical details
A type-confusion bug in the Seroval library (≤ 1.5.2) used by TanStack Start allows an attacker to craft a JSON body that, when deserialized, triggers the invocation of a different client-referenced server function as a side effect. This occurs because adapter payloads could be confused with internal Seroval node types. The attack requires the target function to be client-referenced; server-only functions are not reachable. While the target function's middleware (auth, validation) still executes, request-level middleware does not re-run for the inner invocation, and observability tools may log the wrong endpoint. The issue is fixed in @tanstack/start-server-core 1.167.30 by updating Seroval to 1.5.3 and adding defense-in-depth to the serialization adapter.
Affected products
- TanStack @tanstack/start-server-core < 1.167.30
Timeline
- 2026-05-08: disclosed
- 2026-05-14: advisory