<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T08:38:41.671148+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-332328</id>
    <title>EUVD-2026-332328</title>
    <updated>2026-10-06T08:38:41.720211+00:00</updated>
    <content>EUVD-2026-332328</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-332328"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54074</id>
    <title>fkie_cve-2026-54074</title>
    <updated>2026-10-06T08:38:41.720248+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tina is a headless content management system. @tinacms/cli versions prior to 2.4.3 contain a Remote Code Execution vulnerability in the Forestry-to-Tina migration command. The internal helper addVariablesToCode unquotes any value matching the marker "__TINA_INTERNAL__:::(.*?):::" inside the stringified collection JSON. User-supplied label and name fields from .forestry/**/*.yml are placed into that JSON without any sanitisation. An attacker who controls a Forestry-style project can therefore inject arbitrary JavaScript into the generated tina/templates.{ts,js} file. The injected code is written at module top level, so it executes the moment the developer runs tinacms dev or tinacms build, with the developer's privileges. This issue has been fixed in version 2.4.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54074"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4936-9hrh-qqpw</id>
    <title>GHSA-4936-9hrh-qqpw — @tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in us…</title>
    <updated>2026-10-06T08:38:41.720286+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @tinacms/cli</p>
<p>## Description</p>
<p>### Summary</p>
<p>`@tinacms/cli` contains a Remote Code Execution vulnerability in its
Forestry-to-Tina migration command. The internal helper `addVariablesToCode`
unquotes any value matching the marker `"__TINA_INTERNAL__:::(.*?):::"`
inside the stringified collection JSON. User-supplied `label` and `name`
fields from `.forestry/**/*.yml` are placed into that JSON without any
sanitisation. An attacker who controls a Forestry-style project can therefore
inject arbitrary JavaScript into the generated `tina/templates.{ts,js}`
file. The injected code is written at module top level, so it executes
**the moment the developer runs `tinacms dev` or `tinacms build`**, with the
developer's privileges.</p>
<p>### Details</p>
<p>**Vulnerable code path:**</p>
<p>1. `packages/@tinacms/cli/src/cmds/forestry-migrate/util/index.ts`
   — `transformForestryFieldsToTinaFields()` writes `forestryField.label`
   (and `.name`) straight into TinaField objects (no sanitisation).
2. `packages/@tinacms/cli/src/cmds/forestry-migrate/util/codeTransformer.ts`,
   lines 16-22 — the regex-based unquoter:</p>
<p>```ts
   export const addVariablesToCode = (codeWithTinaPrefix: string) =&gt; {
     const code = codeWithTinaPrefix.replace(
       /"__TINA_INTERNAL__:::(.*?):::"/g,
       '$1'
     );
     return { code };
   };
   ```</p>
<p>3. `codeTransformer.ts` lines 80-88 — the field array is
   `JSON.stringify`-ed and then handed to `addVariablesToCode`. Because
   `JSON.stringify` does **not** escape single quotes or back…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4936-9hrh-qqpw"/>
  </entry>
</feed>
