tanstack-start
Warn
Audited by Snyk on Aug 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the required runtime workflow described by
createFileRoute/server.handlersAPI routes (e.g.,/api/postsand middleware/server functions), outsider-authored free text from HTTP request bodies (e.g.,await request.json(),await request.text(),request.formData()) is ingested directly by the server-side handlers at runtime.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata