<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T12:28:41.730357+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-370767</id>
    <title>EUVD-2026-370767</title>
    <updated>2026-10-06T12:28:41.782327+00:00</updated>
    <content>EUVD-2026-370767</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-370767"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63506</id>
    <title>fkie_cve-2026-63506</title>
    <updated>2026-10-06T12:28:41.782367+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected TinaCloud app instead of the self-hosted site's configured app. An attacker with any TinaCloud account can submit the attacker's own app ID and valid token to a victim endpoint, causing TinaCloudBackendAuthProvider or an affected media authorized callback to accept the attacker's verified status across the tenant boundary. The vulnerable logic is present in packages/@tinacms/auth/src/index.ts and packages/next-tinacms-azure/src/auth.ts. Successful exploitation permits media listing, reading, upload, or deletion and, when TinaCloudBackendAuthProvider is used, GraphQL read, create, update, and delete operations on the victim's content without a victim account or victim interaction. This vulnerability is fixed in @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-63506"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g74q-6g2f-874x</id>
    <title>GHSA-g74q-6g2f-874x — Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site</title>
    <updated>2026-10-06T12:28:41.782408+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @tinacms/auth, npm: next-tinacms-azure</p>
<p>## Summary
 
`@tinacms/auth`'s `isAuthorized(req)` decides authorization by validating the caller's bearer token against `https://identity.tinajs.io/v2/apps/${req.query.clientID}/currentUser`, where the `clientID` comes from the request and is never compared to the site's own configured TinaCloud app id. The function answers "is this token a verified user of whatever app the caller named?" instead of "is this token a verified user of THIS site?"
 
Any TinaCloud user can create their own free app, get a valid token for it, and send `?clientID=&lt;their-own-app&gt;` plus `Authorization: &lt;their-own-token&gt;` to a victim self-hosted site. The victim's `authorized` callback runs `const user = await isAuthorized(req); return user &amp;&amp; user.verified`, which returns `true`, and the victim authorizes the attacker.
 
The attacker holds no account on the victim and needs no victim interaction. With the media handlers this grants read, upload, and delete on the victim's media bucket. When the backend uses `TinaCloudBackendAuthProvider()` (the default the `tinacms init` wizard generates for TinaCloud auth), it grants full GraphQL read, write, and delete of the victim's content.</p>
<p>## Affected code (confirmed at `5a6839f`)
 
`packages/@tinacms/auth/src/index.ts:71-88` reads the `clientID` from the request:
 
```ts
export const isAuthorized = async (req: NextApiRequest) =&gt; {
  const clientID = req.query.clientID;     // attacker-controlled
  const token = req.headers.authorization; // attacker-control…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g74q-6g2f-874x"/>
  </entry>
</feed>
