Toolsvia VibeBuilder SpaceOriginal source ↗ A TanStack Start flaw affects some AI-built apps. Here is the fix, plus Sonnet 5.5 in Replit, Lovable and Microsoft, and upcoming events.
## TL;DR
1. A security flaw (CVE-2026-102989) was disclosed in TanStack Start, a framework many AI-built apps use. Lovable-hosted apps are protected; apps hosted elsewhere need an update and a redeploy.
2. Anthropic released Claude Sonnet 5.5 on Sep 28, and Replit added it to Power Mode on Oct 2.
3. Lovable added Microsoft 365 connectors and Microsoft sign-in, and a voice feature built on GPT Live.
## Top Story: TanStack Start Patch for Apps Built with AI
On Sep 30, the TanStack team published a security advisory for a reflected cross-site scripting (XSS) flaw in TanStack Start. In plain English: an attacker could craft a link that makes a vulnerable app show attacker-controlled content, which can run malicious code in a visitor's browser. TanStack says it affects server-function handling in several react-start, solid-start, vue-start and start-server-core versions, and that fixed versions are out.
Lovable published its own post the same day. Lovable says a researcher found the issue on Sep 14, that it reported it to the maintainers, and that it added firewall rules for hosted apps. Lovable also says it saw no active exploitation, and that the fix applies on your next edit or immediately from the Security page.
**Why it matters to beginners:** you did not write this code, but you ship it. Check whether your project uses TanStack Start, update it, and redeploy. Updating on your computer alone does not fix the live site.
**Why it matters to business owners:** a flaw like this can put customer trust at risk even when your own code is fine. If your app is hosted outside Lovable, ask whoever built it to confirm the update and redeploy are done.
## Plans and Pricing
1. **Claude Sonnet 5.5 (Sep 28):** Anthropic lists API prices of $2 per million input tokens and $10 per million output tokens. Anthropic says it is 30%+ faster and costs up to 30% less than Sonnet 5 for most work. These are vendor claims.
2. **Replit (Oct 2):** Replit's changelog lists Claude Sonnet 5.5 in Power Mode and GPT-6.1 Sol in Max Mode. Check what each mode costs on your plan before switching.
3. **Lovable (Sep 28 and Oct 1):** Microsoft 365 connectors, Fabric integration and Microsoft sign-in work on all plans, per Lovable. Workspace sign-in with Microsoft Entra needs Business or Enterprise. Business and Enterprise also got IP allowlists for API keys, and Enterprise admins can turn on EU-only AI processing.
4. **Windsurf, now under Devin Desktop (Sep 29):** you can sign in with ChatGPT and bill GPT model use to a ChatGPT Plus or Pro plan, per the vendor changelog.
5. **Vercel AI Gateway (Oct 1):** Vercel lists the Laya model as free through Oct 31, 2026, when served by Boundless.
## Security Watch
1. **Check your TanStack Start version.** The advisory lists affected ranges, for example react-start 1.143.12 through 1.168.59, with fixes starting at 1.168.60. Update, then redeploy.
2. **Lovable API key controls (Oct 1):** Business and Enterprise plans can restrict API keys to approved IP addresses. If you share keys with clients or tools, this limits damage if a key leaks.
3. **Vercel Sandbox (Sep 30):** Vercel says Sandbox now supports Secure Compute connectivity, which matters if your agent runs code against private services.
## Not Seen This Week
No verified credit, usage-limit or price changes from Lovable, Replit, Cursor or Bolt.new inside the Sep 28 to Oct 5 window. Cursor's newest changelog entry was Sep 23, so it is left out. Claude Code releases ship often, but the changelog I could read has no dates, so they are left out. Also noted: Bolt.new announced its first acquisition, Dokai, on Sep 29, with agent features promised this fall.
## Try This Week
1. Open your project's package.json, search for tanstack, and confirm you are on a fixed version. Redeploy afterward.
2. If you build on Replit, try the same small task in Power Mode with Claude Sonnet 5.5 and compare it with your usual setting.
3. In Lovable, try the new GPT Live voice feature (Oct 1) in a small test app, such as a spoken FAQ for your business.
## Events: Next 30 Days
Oct 15: LA Tech Week Vibe Coding Camp, Los Angeles, 10 AM to 6 PM PT, free, per the AllAI Events listing.
Oct 16-18: JunctionX Turku Hackathon, Turku, Finland, per the Lovable community events listing.
Oct 18-22: Lisbon AI Week, Lisbon, Portugal, per the Lovable community events listing.
## Join the Conversation
Questions about the TanStack fix or anything above? Join the free VibeBuilder Facebook group at facebook.com/groups/1113060757712466 and share what you are building. To get this roundup every Monday, subscribe to the newsletter on vibebuilder.space.
## Sources
TanStack Start Security Update CVE-2026-102989: tanstack.com/blog/tanstack-start-security-update-cve-2026-102989
A vulnerability in TanStack Start: lovable.dev/blog/how-lovable-protects-your-app-from-a-tanstack-start-vulnerability
Lovable + Microsoft: lovable.dev/blog/microsoft-partnership
Lovable Changelog (Oct 1): docs.lovable.dev/changelog
Introducing Claude Sonnet 5.5: anthropic.com/claude-sonnet-5-5
Replit Updates (Oct 2): docs.replit.com/updates
Devin Desktop Changelog: docs.devin.ai/desktop/changelog
Vercel Changelog: vercel.com/changelog
Bolt.new Blog: bolt.new/blog
Cursor Changelog: cursor.com/changelog
LA Tech Week Vibe Coding Camp: allai.events/event/-la-tech-week-vibe-coding-camp--build-fast-ship-faster-learn-the-entire-ai-dev-stack
Lovable Community Events: whos-local.lovable.app/events
Read the full story →Communityvia Hacker News: Claude CodeOriginal source ↗ Pi Pod lets you run custom AI coding agents inside secure, self-hosted sandboxes so you can build software safely on your own terms.
When you start using autonomous AI coding tools, one major question quickly pops up: how do you let an AI write and run code without risking your personal computer or private data? Pi Pod is a new project designed to solve this by running AI coding agents inside isolated sandboxes on your own servers.
Created as an extension for the lightweight Pi agent framework, the tool aims to give creators privacy and control while handling tricky tasks like sandboxing and browser automation. The creator describes it as an effort to handle the boring background infrastructure while keeping setup simple and free from proprietary platform lock-in.
For new builders, this highlights a big trend in AI development. You do not always have to rely entirely on closed ecosystems to run smart agents. Tools like this give you a safe, private playground to experiment with autonomous coding workflows as you grow your technical skills.
Community discussion: https://news.ycombinator.com/item?id=49937304
Read the full story →