Search

Find a vulnerability

Search criteria

    16 vulnerabilities by @tinacms

    CVE-2026-108261 (GCVE-0-2026-108261)

    Vulnerability from nvd – Published: 2026-10-09 20:43 – Updated: 2026-10-09 20:43
    VLAI
    Title
    TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment
    Summary
    Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL through packages/@tinacms/app/src/preview.tsx, while packages/@tinacms/app/src/lib/preview-origin.ts derives expectedOrigin from that same URL for the GraphQL message channel in packages/@tinacms/app/src/lib/graphql-reducer.ts. An unauthenticated attacker can send a crafted link to a signed-in editor, cause the admin to frame an attacker origin, and have that frame treated as the trusted preview. The attacker-controlled frame can submit GraphQL reads or mutations that the admin executes with the editor credentials, exposing or modifying protected content. This issue is fixed in tinacms 3.14.0 and @tinacms/app 2.5.14.
    CWE
    • CWE-346 - Origin Validation Error
    • CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')
    • CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "tinacms",
              "vendor": "tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 3.14.0"
                }
              ]
            },
            {
              "product": "app",
              "vendor": "@tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.5.14"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL through packages/@tinacms/app/src/preview.tsx, while packages/@tinacms/app/src/lib/preview-origin.ts derives expectedOrigin from that same URL for the GraphQL message channel in packages/@tinacms/app/src/lib/graphql-reducer.ts. An unauthenticated attacker can send a crafted link to a signed-in editor, cause the admin to frame an attacker origin, and have that frame treated as the trusted preview. The attacker-controlled frame can submit GraphQL reads or mutations that the admin executes with the editor credentials, exposing or modifying protected content. This issue is fixed in tinacms 3.14.0 and @tinacms/app 2.5.14."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-346",
                  "description": "CWE-346: Origin Validation Error",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-441",
                  "description": "CWE-441: Unintended Proxy or Intermediary (\u0027Confused Deputy\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-601",
                  "description": "CWE-601: URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-09T20:43:37.580Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/tinacms/tinacms/security/advisories/GHSA-x34j-47hf-4xg7",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-x34j-47hf-4xg7"
            },
            {
              "name": "https://github.com/tinacms/tinacms/pull/7522",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/pull/7522"
            },
            {
              "name": "https://github.com/tinacms/tinacms/commit/b57dbf4b56201aef15cd92caa49fd12ab96bbecf",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/commit/b57dbf4b56201aef15cd92caa49fd12ab96bbecf"
            },
            {
              "name": "https://github.com/tinacms/tinacms/releases/tag/@tinacms/app@2.5.14",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/releases/tag/@tinacms/app@2.5.14"
            },
            {
              "name": "https://github.com/tinacms/tinacms/releases/tag/tinacms@3.14.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/releases/tag/tinacms@3.14.0"
            }
          ],
          "source": {
            "advisory": "GHSA-x34j-47hf-4xg7",
            "discovery": "UNKNOWN"
          },
          "title": "TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-108261",
        "datePublished": "2026-10-09T20:43:37.580Z",
        "dateReserved": "2026-10-09T17:33:15.410Z",
        "dateUpdated": "2026-10-09T20:43:37.580Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-108260 (GCVE-0-2026-108260)

    Vulnerability from nvd – Published: 2026-10-09 20:40 – Updated: 2026-10-09 20:40
    VLAI
    Title
    @tinacms/web-components: `tina-markdown` writes rich-text link URLs into `href` without scheme validation, allowing stored XSS
    Summary
    Tina is a headless content management system. Prior to 0.2.1, the tina-markdown element in packages/@tinacms/web-components/src/tina-markdown.js assigns a rich-text node.url value directly to an anchor href without validating the URL scheme. A content author can store a link using a script-capable scheme, and a visitor who clicks the rendered link executes attacker-controlled script in the site's origin. The script can access same-origin application data and, when the visitor is an editor or administrator, may expose credentials stored by the TinaCMS admin on that origin. This issue is fixed in version 0.2.1.
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    • CWE-83 - Improper Neutralization of Script in Attributes in a Web Page
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "tinacms",
              "vendor": "tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 3.14.0"
                }
              ]
            },
            {
              "product": "web-components",
              "vendor": "@tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 0.2.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Tina is a headless content management system. Prior to 0.2.1, the tina-markdown element in packages/@tinacms/web-components/src/tina-markdown.js assigns a rich-text node.url value directly to an anchor href without validating the URL scheme. A content author can store a link using a script-capable scheme, and a visitor who clicks the rendered link executes attacker-controlled script in the site\u0027s origin. The script can access same-origin application data and, when the visitor is an editor or administrator, may expose credentials stored by the TinaCMS admin on that origin. This issue is fixed in version 0.2.1."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.6,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-83",
                  "description": "CWE-83: Improper Neutralization of Script in Attributes in a Web Page",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-09T20:40:37.228Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/tinacms/tinacms/security/advisories/GHSA-c42q-qvc3-j6vg",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-c42q-qvc3-j6vg"
            },
            {
              "name": "https://github.com/tinacms/tinacms/pull/7523",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/pull/7523"
            },
            {
              "name": "https://github.com/tinacms/tinacms/commit/5295e077f0d279c35686a0e481a15e33a4877e3b",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/commit/5295e077f0d279c35686a0e481a15e33a4877e3b"
            },
            {
              "name": "https://github.com/tinacms/tinacms/releases/tag/@tinacms/web-components@0.2.1",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/releases/tag/@tinacms/web-components@0.2.1"
            }
          ],
          "source": {
            "advisory": "GHSA-c42q-qvc3-j6vg",
            "discovery": "UNKNOWN"
          },
          "title": "@tinacms/web-components: `tina-markdown` writes rich-text link URLs into `href` without scheme validation, allowing stored XSS"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-108260",
        "datePublished": "2026-10-09T20:40:37.228Z",
        "dateReserved": "2026-10-09T17:33:15.409Z",
        "dateUpdated": "2026-10-09T20:40:37.228Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-108259 (GCVE-0-2026-108259)

    Vulnerability from nvd – Published: 2026-10-09 20:36 – Updated: 2026-10-09 20:37
    VLAI
    Title
    Tina: Code injection via unescaped Git branch name in generated client source
    Summary
    Tina is a headless content management system. Prior to 3.0.0, @tinacms/cli reads Git branch values from VERCEL_GIT_COMMIT_REF, GITHUB_BRANCH, or HEAD, incorporates the raw value into the API URL, and interpolates that URL into JavaScript string literals in packages/@tinacms/cli/src/next/codegen/index.ts and packages/@tinacms/cli/src/next/codegen/codegen/plugin.ts. A crafted Git-valid branch name containing a quote can terminate the generated string and inject an expression that executes when the generated client module is imported during a preview build. The injected code runs with the build process privileges and can read environment credentials, modify deployment artifacts, or make network requests. This issue is fixed in version 3.0.0.
    CWE
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "tinacms",
              "vendor": "tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 3.0.0"
                }
              ]
            },
            {
              "product": "cli",
              "vendor": "@tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 3.0.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Tina is a headless content management system. Prior to 3.0.0, @tinacms/cli reads Git branch values from VERCEL_GIT_COMMIT_REF, GITHUB_BRANCH, or HEAD, incorporates the raw value into the API URL, and interpolates that URL into JavaScript string literals in packages/@tinacms/cli/src/next/codegen/index.ts and packages/@tinacms/cli/src/next/codegen/codegen/plugin.ts. A crafted Git-valid branch name containing a quote can terminate the generated string and inject an expression that executes when the generated client module is imported during a preview build. The injected code runs with the build process privileges and can read environment credentials, modify deployment artifacts, or make network requests. This issue is fixed in version 3.0.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "CWE-94: Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-09T20:37:19.094Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/tinacms/tinacms/security/advisories/GHSA-pwhx-cvv3-qj5c",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-pwhx-cvv3-qj5c"
            },
            {
              "name": "https://github.com/tinacms/tinacms/pull/7526",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/pull/7526"
            },
            {
              "name": "https://github.com/tinacms/tinacms/commit/d030d414d39e15de79bf36e4c728d57205e71dde",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/commit/d030d414d39e15de79bf36e4c728d57205e71dde"
            },
            {
              "name": "https://github.com/tinacms/tinacms/releases/tag/@tinacms/cli@3.0.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/releases/tag/@tinacms/cli@3.0.0"
            }
          ],
          "source": {
            "advisory": "GHSA-pwhx-cvv3-qj5c",
            "discovery": "UNKNOWN"
          },
          "title": "Tina: Code injection via unescaped Git branch name in generated client source"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-108259",
        "datePublished": "2026-10-09T20:36:41.777Z",
        "dateReserved": "2026-10-09T17:33:15.409Z",
        "dateUpdated": "2026-10-09T20:37:19.094Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-63506 (GCVE-0-2026-63506)

    Vulnerability from nvd – Published: 2026-09-16 20:27 – Updated: 2026-09-17 15:54
    VLAI
    Title
    Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
    Summary
    Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected TinaCloud app instead of the self-hosted site's configured app. An attacker with any TinaCloud account can submit the attacker's own app ID and valid token to a victim endpoint, causing TinaCloudBackendAuthProvider or an affected media authorized callback to accept the attacker's verified status across the tenant boundary. The vulnerable logic is present in packages/@tinacms/auth/src/index.ts and packages/next-tinacms-azure/src/auth.ts. Successful exploitation permits media listing, reading, upload, or deletion and, when TinaCloudBackendAuthProvider is used, GraphQL read, create, update, and delete operations on the victim's content without a victim account or victim interaction. This vulnerability is fixed in @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 15:54 UTC
    CWE
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-63506",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T15:54:06.674922Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T15:54:38.071Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-g74q-6g2f-874x"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "tinacms",
              "vendor": "tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.1.4"
                }
              ]
            },
            {
              "product": "auth",
              "vendor": "@tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.1.4"
                }
              ]
            },
            {
              "product": "next-tinacms-azure",
              "vendor": "tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 15.0.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected TinaCloud app instead of the self-hosted site\u0027s configured app. An attacker with any TinaCloud account can submit the attacker\u0027s own app ID and valid token to a victim endpoint, causing TinaCloudBackendAuthProvider or an affected media authorized callback to accept the attacker\u0027s verified status across the tenant boundary. The vulnerable logic is present in packages/@tinacms/auth/src/index.ts and packages/next-tinacms-azure/src/auth.ts. Successful exploitation permits media listing, reading, upload, or deletion and, when TinaCloudBackendAuthProvider is used, GraphQL read, create, update, and delete operations on the victim\u0027s content without a victim account or victim interaction. This vulnerability is fixed in @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639: Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T20:27:37.385Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/tinacms/tinacms/security/advisories/GHSA-g74q-6g2f-874x",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-g74q-6g2f-874x"
            },
            {
              "name": "https://github.com/tinacms/tinacms/pull/7168",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/pull/7168"
            },
            {
              "name": "https://github.com/tinacms/tinacms/commit/0a927a4f8d228dd05ee7ca4be32899bc190e73af",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/commit/0a927a4f8d228dd05ee7ca4be32899bc190e73af"
            },
            {
              "name": "https://github.com/tinacms/tinacms/releases/tag/@tinacms/auth@1.1.4",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/releases/tag/@tinacms/auth@1.1.4"
            },
            {
              "name": "https://github.com/tinacms/tinacms/releases/tag/next-tinacms-azure@15.0.1",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/releases/tag/next-tinacms-azure@15.0.1"
            }
          ],
          "source": {
            "advisory": "GHSA-g74q-6g2f-874x",
            "discovery": "UNKNOWN"
          },
          "title": "Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-63506",
        "datePublished": "2026-09-16T20:27:37.385Z",
        "dateReserved": "2026-07-16T21:49:52.069Z",
        "dateUpdated": "2026-09-17T15:54:38.071Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-29066 (GCVE-0-2026-29066)

    Vulnerability from nvd – Published: 2026-03-12 16:57 – Updated: 2026-03-13 16:27
    VLAI
    Title
    Arbitrary File Read via Disabled Vite Filesystem Restriction in TinaCMS CLI
    Summary
    Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite's built-in filesystem access restriction. This allows any unauthenticated attacker who can reach the dev server to read arbitrary files on the host system. This vulnerability is fixed in 2.1.8.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-03-13 16:27 UTC
    CWE
    • CWE-552 - Files or Directories Accessible to External Parties
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    References
    Impacted products
    Vendor Product Version
    @tinacms cli Affected: < 2.1.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-29066",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-13T16:27:18.883170Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-13T16:27:22.344Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-m48g-4wr2-j2h6"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "cli",
              "vendor": "@tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.1.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite\u0027s built-in filesystem access restriction. This allows any unauthenticated attacker who can reach the dev server to read arbitrary files on the host system. This vulnerability is fixed in 2.1.8."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 6.2,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-552",
                  "description": "CWE-552: Files or Directories Accessible to External Parties",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-03-12T16:57:41.393Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/tinacms/tinacms/security/advisories/GHSA-m48g-4wr2-j2h6",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-m48g-4wr2-j2h6"
            }
          ],
          "source": {
            "advisory": "GHSA-m48g-4wr2-j2h6",
            "discovery": "UNKNOWN"
          },
          "title": "Arbitrary File Read via Disabled Vite Filesystem Restriction in TinaCMS CLI"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-29066",
        "datePublished": "2026-03-12T16:57:41.393Z",
        "dateReserved": "2026-03-03T20:51:43.482Z",
        "dateUpdated": "2026-03-13T16:27:22.344Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-28793 (GCVE-0-2026-28793)

    Vulnerability from nvd – Published: 2026-03-12 16:50 – Updated: 2026-03-13 16:28
    VLAI
    Title
    Path Traversal Leading to Arbitrary File Read, Write and Delete in TinaCMS
    Summary
    Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path traversal, allowing attackers to read and write arbitrary files on the filesystem outside the intended media directory. When running tinacms dev, the CLI starts a local HTTP server (default port 4001) exposing endpoints such as /media/list/*, /media/upload/*, and /media/*. These endpoints process user-controlled path segments using decodeURI() and path.join() without validating that the resolved path remains within the configured media directory. This vulnerability is fixed in 2.1.8.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-03-13 16:28 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    Impacted products
    Vendor Product Version
    @tinacms cli Affected: < 2.1.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-28793",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-13T16:28:28.663530Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-13T16:28:33.184Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-2f24-mg4x-534q"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "cli",
              "vendor": "@tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.1.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path traversal, allowing attackers to read and write arbitrary files on the filesystem outside the intended media directory. When running tinacms dev, the CLI starts a local HTTP server (default port 4001) exposing endpoints such as /media/list/*, /media/upload/*, and /media/*. These endpoints process user-controlled path segments using decodeURI() and path.join() without validating that the resolved path remains within the configured media directory. This vulnerability is fixed in 2.1.8."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 8.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-03-12T16:50:20.132Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/tinacms/tinacms/security/advisories/GHSA-2f24-mg4x-534q",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-2f24-mg4x-534q"
            }
          ],
          "source": {
            "advisory": "GHSA-2f24-mg4x-534q",
            "discovery": "UNKNOWN"
          },
          "title": "Path Traversal Leading to Arbitrary File Read, Write and Delete in TinaCMS"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-28793",
        "datePublished": "2026-03-12T16:50:20.132Z",
        "dateReserved": "2026-03-03T14:25:19.245Z",
        "dateUpdated": "2026-03-13T16:28:33.184Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-28792 (GCVE-0-2026-28792)

    Vulnerability from nvd – Published: 2026-03-12 16:48 – Updated: 2026-03-13 16:29
    VLAI
    Title
    Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS
    Summary
    Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Allow-Origin: *) with the path traversal vulnerability (previously reported) to enable a browser-based drive-by attack. A remote attacker can enumerate the filesystem, write arbitrary files, and delete arbitrary files on developer's machines by simply tricking them into visiting a malicious website while tinacms dev is running. This vulnerability is fixed in 2.1.8.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-03-13 16:29 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    • CWE-942 - Permissive Cross-domain Policy with Untrusted Domains
    References
    Impacted products
    Vendor Product Version
    @tinacms cli Affected: < 2.1.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-28792",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-13T16:29:02.569938Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-13T16:29:06.236Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-8pw3-9m7f-q734"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "cli",
              "vendor": "@tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.1.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Allow-Origin: *) with the path traversal vulnerability (previously reported) to enable a browser-based drive-by attack. A remote attacker can enumerate the filesystem, write arbitrary files, and delete arbitrary files on developer\u0027s machines by simply tricking them into visiting a malicious website while tinacms dev is running. This vulnerability is fixed in 2.1.8."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.7,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-942",
                  "description": "CWE-942: Permissive Cross-domain Policy with Untrusted Domains",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-03-12T16:48:16.461Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/tinacms/tinacms/security/advisories/GHSA-8pw3-9m7f-q734",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-8pw3-9m7f-q734"
            }
          ],
          "source": {
            "advisory": "GHSA-8pw3-9m7f-q734",
            "discovery": "UNKNOWN"
          },
          "title": "Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-28792",
        "datePublished": "2026-03-12T16:48:16.461Z",
        "dateReserved": "2026-03-03T14:25:19.245Z",
        "dateUpdated": "2026-03-13T16:29:06.236Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-24125 (GCVE-0-2026-24125)

    Vulnerability from nvd – Published: 2026-03-12 16:31 – Updated: 2026-03-12 17:55
    VLAI
    Title
    Path Traversal in @tinacms/graphql
    Summary
    Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content documents using relative file paths (relativePath, newRelativePath) via GraphQL mutations. Under certain conditions, these paths are combined with the collection path using path.join() without validating that the resolved path remains within the collection root directory. Because path.join() does not prevent directory traversal, paths containing ../ sequences can escape the intended directory boundary. This vulnerability is fixed in 2.1.2.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-03-12 17:54 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    Impacted products
    Vendor Product Version
    @tinacms graphql Affected: < 2.1.2
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-24125",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-12T17:54:30.695250Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-12T17:55:19.636Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "graphql",
              "vendor": "@tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.1.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content documents using relative file paths (relativePath, newRelativePath) via GraphQL mutations. Under certain conditions, these paths are combined with the collection path using path.join() without validating that the resolved path remains within the collection root directory. Because path.join() does not prevent directory traversal, paths containing ../ sequences can escape the intended directory boundary. This vulnerability is fixed in 2.1.2."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-03-12T16:31:56.860Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/tinacms/tinacms/security/advisories/GHSA-2238-xc5r-v9hj",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-2238-xc5r-v9hj"
            }
          ],
          "source": {
            "advisory": "GHSA-2238-xc5r-v9hj",
            "discovery": "UNKNOWN"
          },
          "title": "Path Traversal in @tinacms/graphql"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-24125",
        "datePublished": "2026-03-12T16:31:56.860Z",
        "dateReserved": "2026-01-21T18:38:22.473Z",
        "dateUpdated": "2026-03-12T17:55:19.636Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-108261 (GCVE-0-2026-108261)

    Vulnerability from cvelistv5 – Published: 2026-10-09 20:43 – Updated: 2026-10-09 20:43
    VLAI
    Title
    TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment
    Summary
    Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL through packages/@tinacms/app/src/preview.tsx, while packages/@tinacms/app/src/lib/preview-origin.ts derives expectedOrigin from that same URL for the GraphQL message channel in packages/@tinacms/app/src/lib/graphql-reducer.ts. An unauthenticated attacker can send a crafted link to a signed-in editor, cause the admin to frame an attacker origin, and have that frame treated as the trusted preview. The attacker-controlled frame can submit GraphQL reads or mutations that the admin executes with the editor credentials, exposing or modifying protected content. This issue is fixed in tinacms 3.14.0 and @tinacms/app 2.5.14.
    CWE
    • CWE-346 - Origin Validation Error
    • CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')
    • CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "tinacms",
              "vendor": "tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 3.14.0"
                }
              ]
            },
            {
              "product": "app",
              "vendor": "@tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.5.14"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL through packages/@tinacms/app/src/preview.tsx, while packages/@tinacms/app/src/lib/preview-origin.ts derives expectedOrigin from that same URL for the GraphQL message channel in packages/@tinacms/app/src/lib/graphql-reducer.ts. An unauthenticated attacker can send a crafted link to a signed-in editor, cause the admin to frame an attacker origin, and have that frame treated as the trusted preview. The attacker-controlled frame can submit GraphQL reads or mutations that the admin executes with the editor credentials, exposing or modifying protected content. This issue is fixed in tinacms 3.14.0 and @tinacms/app 2.5.14."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-346",
                  "description": "CWE-346: Origin Validation Error",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-441",
                  "description": "CWE-441: Unintended Proxy or Intermediary (\u0027Confused Deputy\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-601",
                  "description": "CWE-601: URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-09T20:43:37.580Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/tinacms/tinacms/security/advisories/GHSA-x34j-47hf-4xg7",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-x34j-47hf-4xg7"
            },
            {
              "name": "https://github.com/tinacms/tinacms/pull/7522",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/pull/7522"
            },
            {
              "name": "https://github.com/tinacms/tinacms/commit/b57dbf4b56201aef15cd92caa49fd12ab96bbecf",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/commit/b57dbf4b56201aef15cd92caa49fd12ab96bbecf"
            },
            {
              "name": "https://github.com/tinacms/tinacms/releases/tag/@tinacms/app@2.5.14",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/releases/tag/@tinacms/app@2.5.14"
            },
            {
              "name": "https://github.com/tinacms/tinacms/releases/tag/tinacms@3.14.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/releases/tag/tinacms@3.14.0"
            }
          ],
          "source": {
            "advisory": "GHSA-x34j-47hf-4xg7",
            "discovery": "UNKNOWN"
          },
          "title": "TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-108261",
        "datePublished": "2026-10-09T20:43:37.580Z",
        "dateReserved": "2026-10-09T17:33:15.410Z",
        "dateUpdated": "2026-10-09T20:43:37.580Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-108260 (GCVE-0-2026-108260)

    Vulnerability from cvelistv5 – Published: 2026-10-09 20:40 – Updated: 2026-10-09 20:40
    VLAI
    Title
    @tinacms/web-components: `tina-markdown` writes rich-text link URLs into `href` without scheme validation, allowing stored XSS
    Summary
    Tina is a headless content management system. Prior to 0.2.1, the tina-markdown element in packages/@tinacms/web-components/src/tina-markdown.js assigns a rich-text node.url value directly to an anchor href without validating the URL scheme. A content author can store a link using a script-capable scheme, and a visitor who clicks the rendered link executes attacker-controlled script in the site's origin. The script can access same-origin application data and, when the visitor is an editor or administrator, may expose credentials stored by the TinaCMS admin on that origin. This issue is fixed in version 0.2.1.
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    • CWE-83 - Improper Neutralization of Script in Attributes in a Web Page
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "tinacms",
              "vendor": "tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 3.14.0"
                }
              ]
            },
            {
              "product": "web-components",
              "vendor": "@tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 0.2.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Tina is a headless content management system. Prior to 0.2.1, the tina-markdown element in packages/@tinacms/web-components/src/tina-markdown.js assigns a rich-text node.url value directly to an anchor href without validating the URL scheme. A content author can store a link using a script-capable scheme, and a visitor who clicks the rendered link executes attacker-controlled script in the site\u0027s origin. The script can access same-origin application data and, when the visitor is an editor or administrator, may expose credentials stored by the TinaCMS admin on that origin. This issue is fixed in version 0.2.1."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.6,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-83",
                  "description": "CWE-83: Improper Neutralization of Script in Attributes in a Web Page",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-09T20:40:37.228Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/tinacms/tinacms/security/advisories/GHSA-c42q-qvc3-j6vg",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-c42q-qvc3-j6vg"
            },
            {
              "name": "https://github.com/tinacms/tinacms/pull/7523",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/pull/7523"
            },
            {
              "name": "https://github.com/tinacms/tinacms/commit/5295e077f0d279c35686a0e481a15e33a4877e3b",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/commit/5295e077f0d279c35686a0e481a15e33a4877e3b"
            },
            {
              "name": "https://github.com/tinacms/tinacms/releases/tag/@tinacms/web-components@0.2.1",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/releases/tag/@tinacms/web-components@0.2.1"
            }
          ],
          "source": {
            "advisory": "GHSA-c42q-qvc3-j6vg",
            "discovery": "UNKNOWN"
          },
          "title": "@tinacms/web-components: `tina-markdown` writes rich-text link URLs into `href` without scheme validation, allowing stored XSS"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-108260",
        "datePublished": "2026-10-09T20:40:37.228Z",
        "dateReserved": "2026-10-09T17:33:15.409Z",
        "dateUpdated": "2026-10-09T20:40:37.228Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-108259 (GCVE-0-2026-108259)

    Vulnerability from cvelistv5 – Published: 2026-10-09 20:36 – Updated: 2026-10-09 20:37
    VLAI
    Title
    Tina: Code injection via unescaped Git branch name in generated client source
    Summary
    Tina is a headless content management system. Prior to 3.0.0, @tinacms/cli reads Git branch values from VERCEL_GIT_COMMIT_REF, GITHUB_BRANCH, or HEAD, incorporates the raw value into the API URL, and interpolates that URL into JavaScript string literals in packages/@tinacms/cli/src/next/codegen/index.ts and packages/@tinacms/cli/src/next/codegen/codegen/plugin.ts. A crafted Git-valid branch name containing a quote can terminate the generated string and inject an expression that executes when the generated client module is imported during a preview build. The injected code runs with the build process privileges and can read environment credentials, modify deployment artifacts, or make network requests. This issue is fixed in version 3.0.0.
    CWE
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "tinacms",
              "vendor": "tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 3.0.0"
                }
              ]
            },
            {
              "product": "cli",
              "vendor": "@tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 3.0.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Tina is a headless content management system. Prior to 3.0.0, @tinacms/cli reads Git branch values from VERCEL_GIT_COMMIT_REF, GITHUB_BRANCH, or HEAD, incorporates the raw value into the API URL, and interpolates that URL into JavaScript string literals in packages/@tinacms/cli/src/next/codegen/index.ts and packages/@tinacms/cli/src/next/codegen/codegen/plugin.ts. A crafted Git-valid branch name containing a quote can terminate the generated string and inject an expression that executes when the generated client module is imported during a preview build. The injected code runs with the build process privileges and can read environment credentials, modify deployment artifacts, or make network requests. This issue is fixed in version 3.0.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "CWE-94: Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-09T20:37:19.094Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/tinacms/tinacms/security/advisories/GHSA-pwhx-cvv3-qj5c",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-pwhx-cvv3-qj5c"
            },
            {
              "name": "https://github.com/tinacms/tinacms/pull/7526",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/pull/7526"
            },
            {
              "name": "https://github.com/tinacms/tinacms/commit/d030d414d39e15de79bf36e4c728d57205e71dde",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/commit/d030d414d39e15de79bf36e4c728d57205e71dde"
            },
            {
              "name": "https://github.com/tinacms/tinacms/releases/tag/@tinacms/cli@3.0.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/releases/tag/@tinacms/cli@3.0.0"
            }
          ],
          "source": {
            "advisory": "GHSA-pwhx-cvv3-qj5c",
            "discovery": "UNKNOWN"
          },
          "title": "Tina: Code injection via unescaped Git branch name in generated client source"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-108259",
        "datePublished": "2026-10-09T20:36:41.777Z",
        "dateReserved": "2026-10-09T17:33:15.409Z",
        "dateUpdated": "2026-10-09T20:37:19.094Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-63506 (GCVE-0-2026-63506)

    Vulnerability from cvelistv5 – Published: 2026-09-16 20:27 – Updated: 2026-09-17 15:54
    VLAI
    Title
    Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
    Summary
    Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected TinaCloud app instead of the self-hosted site's configured app. An attacker with any TinaCloud account can submit the attacker's own app ID and valid token to a victim endpoint, causing TinaCloudBackendAuthProvider or an affected media authorized callback to accept the attacker's verified status across the tenant boundary. The vulnerable logic is present in packages/@tinacms/auth/src/index.ts and packages/next-tinacms-azure/src/auth.ts. Successful exploitation permits media listing, reading, upload, or deletion and, when TinaCloudBackendAuthProvider is used, GraphQL read, create, update, and delete operations on the victim's content without a victim account or victim interaction. This vulnerability is fixed in @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 15:54 UTC
    CWE
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-63506",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T15:54:06.674922Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T15:54:38.071Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-g74q-6g2f-874x"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "tinacms",
              "vendor": "tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.1.4"
                }
              ]
            },
            {
              "product": "auth",
              "vendor": "@tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.1.4"
                }
              ]
            },
            {
              "product": "next-tinacms-azure",
              "vendor": "tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 15.0.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected TinaCloud app instead of the self-hosted site\u0027s configured app. An attacker with any TinaCloud account can submit the attacker\u0027s own app ID and valid token to a victim endpoint, causing TinaCloudBackendAuthProvider or an affected media authorized callback to accept the attacker\u0027s verified status across the tenant boundary. The vulnerable logic is present in packages/@tinacms/auth/src/index.ts and packages/next-tinacms-azure/src/auth.ts. Successful exploitation permits media listing, reading, upload, or deletion and, when TinaCloudBackendAuthProvider is used, GraphQL read, create, update, and delete operations on the victim\u0027s content without a victim account or victim interaction. This vulnerability is fixed in @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639: Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T20:27:37.385Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/tinacms/tinacms/security/advisories/GHSA-g74q-6g2f-874x",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-g74q-6g2f-874x"
            },
            {
              "name": "https://github.com/tinacms/tinacms/pull/7168",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/pull/7168"
            },
            {
              "name": "https://github.com/tinacms/tinacms/commit/0a927a4f8d228dd05ee7ca4be32899bc190e73af",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/commit/0a927a4f8d228dd05ee7ca4be32899bc190e73af"
            },
            {
              "name": "https://github.com/tinacms/tinacms/releases/tag/@tinacms/auth@1.1.4",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/releases/tag/@tinacms/auth@1.1.4"
            },
            {
              "name": "https://github.com/tinacms/tinacms/releases/tag/next-tinacms-azure@15.0.1",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tinacms/tinacms/releases/tag/next-tinacms-azure@15.0.1"
            }
          ],
          "source": {
            "advisory": "GHSA-g74q-6g2f-874x",
            "discovery": "UNKNOWN"
          },
          "title": "Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-63506",
        "datePublished": "2026-09-16T20:27:37.385Z",
        "dateReserved": "2026-07-16T21:49:52.069Z",
        "dateUpdated": "2026-09-17T15:54:38.071Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-29066 (GCVE-0-2026-29066)

    Vulnerability from cvelistv5 – Published: 2026-03-12 16:57 – Updated: 2026-03-13 16:27
    VLAI
    Title
    Arbitrary File Read via Disabled Vite Filesystem Restriction in TinaCMS CLI
    Summary
    Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite's built-in filesystem access restriction. This allows any unauthenticated attacker who can reach the dev server to read arbitrary files on the host system. This vulnerability is fixed in 2.1.8.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-03-13 16:27 UTC
    CWE
    • CWE-552 - Files or Directories Accessible to External Parties
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    References
    Impacted products
    Vendor Product Version
    @tinacms cli Affected: < 2.1.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-29066",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-13T16:27:18.883170Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-13T16:27:22.344Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-m48g-4wr2-j2h6"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "cli",
              "vendor": "@tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.1.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite\u0027s built-in filesystem access restriction. This allows any unauthenticated attacker who can reach the dev server to read arbitrary files on the host system. This vulnerability is fixed in 2.1.8."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 6.2,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-552",
                  "description": "CWE-552: Files or Directories Accessible to External Parties",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-03-12T16:57:41.393Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/tinacms/tinacms/security/advisories/GHSA-m48g-4wr2-j2h6",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-m48g-4wr2-j2h6"
            }
          ],
          "source": {
            "advisory": "GHSA-m48g-4wr2-j2h6",
            "discovery": "UNKNOWN"
          },
          "title": "Arbitrary File Read via Disabled Vite Filesystem Restriction in TinaCMS CLI"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-29066",
        "datePublished": "2026-03-12T16:57:41.393Z",
        "dateReserved": "2026-03-03T20:51:43.482Z",
        "dateUpdated": "2026-03-13T16:27:22.344Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-28793 (GCVE-0-2026-28793)

    Vulnerability from cvelistv5 – Published: 2026-03-12 16:50 – Updated: 2026-03-13 16:28
    VLAI
    Title
    Path Traversal Leading to Arbitrary File Read, Write and Delete in TinaCMS
    Summary
    Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path traversal, allowing attackers to read and write arbitrary files on the filesystem outside the intended media directory. When running tinacms dev, the CLI starts a local HTTP server (default port 4001) exposing endpoints such as /media/list/*, /media/upload/*, and /media/*. These endpoints process user-controlled path segments using decodeURI() and path.join() without validating that the resolved path remains within the configured media directory. This vulnerability is fixed in 2.1.8.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-03-13 16:28 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    Impacted products
    Vendor Product Version
    @tinacms cli Affected: < 2.1.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-28793",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-13T16:28:28.663530Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-13T16:28:33.184Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-2f24-mg4x-534q"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "cli",
              "vendor": "@tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.1.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path traversal, allowing attackers to read and write arbitrary files on the filesystem outside the intended media directory. When running tinacms dev, the CLI starts a local HTTP server (default port 4001) exposing endpoints such as /media/list/*, /media/upload/*, and /media/*. These endpoints process user-controlled path segments using decodeURI() and path.join() without validating that the resolved path remains within the configured media directory. This vulnerability is fixed in 2.1.8."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 8.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-03-12T16:50:20.132Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/tinacms/tinacms/security/advisories/GHSA-2f24-mg4x-534q",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-2f24-mg4x-534q"
            }
          ],
          "source": {
            "advisory": "GHSA-2f24-mg4x-534q",
            "discovery": "UNKNOWN"
          },
          "title": "Path Traversal Leading to Arbitrary File Read, Write and Delete in TinaCMS"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-28793",
        "datePublished": "2026-03-12T16:50:20.132Z",
        "dateReserved": "2026-03-03T14:25:19.245Z",
        "dateUpdated": "2026-03-13T16:28:33.184Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-28792 (GCVE-0-2026-28792)

    Vulnerability from cvelistv5 – Published: 2026-03-12 16:48 – Updated: 2026-03-13 16:29
    VLAI
    Title
    Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS
    Summary
    Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Allow-Origin: *) with the path traversal vulnerability (previously reported) to enable a browser-based drive-by attack. A remote attacker can enumerate the filesystem, write arbitrary files, and delete arbitrary files on developer's machines by simply tricking them into visiting a malicious website while tinacms dev is running. This vulnerability is fixed in 2.1.8.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-03-13 16:29 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    • CWE-942 - Permissive Cross-domain Policy with Untrusted Domains
    References
    Impacted products
    Vendor Product Version
    @tinacms cli Affected: < 2.1.8
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-28792",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-13T16:29:02.569938Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-13T16:29:06.236Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-8pw3-9m7f-q734"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "cli",
              "vendor": "@tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.1.8"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Allow-Origin: *) with the path traversal vulnerability (previously reported) to enable a browser-based drive-by attack. A remote attacker can enumerate the filesystem, write arbitrary files, and delete arbitrary files on developer\u0027s machines by simply tricking them into visiting a malicious website while tinacms dev is running. This vulnerability is fixed in 2.1.8."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.7,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-942",
                  "description": "CWE-942: Permissive Cross-domain Policy with Untrusted Domains",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-03-12T16:48:16.461Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/tinacms/tinacms/security/advisories/GHSA-8pw3-9m7f-q734",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-8pw3-9m7f-q734"
            }
          ],
          "source": {
            "advisory": "GHSA-8pw3-9m7f-q734",
            "discovery": "UNKNOWN"
          },
          "title": "Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-28792",
        "datePublished": "2026-03-12T16:48:16.461Z",
        "dateReserved": "2026-03-03T14:25:19.245Z",
        "dateUpdated": "2026-03-13T16:29:06.236Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-24125 (GCVE-0-2026-24125)

    Vulnerability from cvelistv5 – Published: 2026-03-12 16:31 – Updated: 2026-03-12 17:55
    VLAI
    Title
    Path Traversal in @tinacms/graphql
    Summary
    Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content documents using relative file paths (relativePath, newRelativePath) via GraphQL mutations. Under certain conditions, these paths are combined with the collection path using path.join() without validating that the resolved path remains within the collection root directory. Because path.join() does not prevent directory traversal, paths containing ../ sequences can escape the intended directory boundary. This vulnerability is fixed in 2.1.2.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-03-12 17:54 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    Impacted products
    Vendor Product Version
    @tinacms graphql Affected: < 2.1.2
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-24125",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-12T17:54:30.695250Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-12T17:55:19.636Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "graphql",
              "vendor": "@tinacms",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.1.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content documents using relative file paths (relativePath, newRelativePath) via GraphQL mutations. Under certain conditions, these paths are combined with the collection path using path.join() without validating that the resolved path remains within the collection root directory. Because path.join() does not prevent directory traversal, paths containing ../ sequences can escape the intended directory boundary. This vulnerability is fixed in 2.1.2."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-03-12T16:31:56.860Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/tinacms/tinacms/security/advisories/GHSA-2238-xc5r-v9hj",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-2238-xc5r-v9hj"
            }
          ],
          "source": {
            "advisory": "GHSA-2238-xc5r-v9hj",
            "discovery": "UNKNOWN"
          },
          "title": "Path Traversal in @tinacms/graphql"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-24125",
        "datePublished": "2026-03-12T16:31:56.860Z",
        "dateReserved": "2026-01-21T18:38:22.473Z",
        "dateUpdated": "2026-03-12T17:55:19.636Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }