Medium · 4.7 Node.js & npm GHSA-pwhx-cvv3-qj5c CVE-2026-108259
CVE-2026-108259 — Code injection in @tinacms/cli from unescaped Git branch name
A code-injection vulnerability in @tinacms/cli allows a crafted Git branch name to inject code into a generated client module used during preview builds. The issue is fixed in 3.0.0. (Sources: 4023, 32645, 32357)
AI summary
Tina's @tinacms/cli contains a code-injection vulnerability that can be triggered by a specially crafted Git branch name embedded into generated client source. The vulnerability is tracked as CVE-2026-108259 and is fixed in 3.0.0. (Sources: 4023, 32645, 32357)
What happened
@tinacms/cli reads Git branch values from environment variables VERCEL_GIT_COMMIT_REF, GITHUB_BRANCH, or from HEAD and incorporates the raw value into an API URL that is interpolated into generated JavaScript string literals. A Git-valid branch name containing a quote can terminate the generated string and inject an expression that executes when the generated client module is imported during a preview build. (Sources: 4023, 32645, 32357)
Technical cause
The generated client source in @tinacms/cli inserts the branch value directly into JavaScript string literals in the codegen implementation (files named in the advisory). Because the branch value is not escaped before interpolation, a crafted branch name that includes a quote character can break out of the literal and inject executable code into the generated module. (Sources: 4023, 32645)
Why this matters
Injected code executes with the privileges of the build process during import of the generated client module. The advisory states the injected code can read environment credentials, modify deployment artifacts, or make network requests. This can expose secrets or alter build outputs. (Sources: 4023, 32645)
Who is affected
Projects that use the @tinacms/cli package and perform preview builds which import the generated client module are at risk. The issue arises when branch names are read from VERCEL_GIT_COMMIT_REF, GITHUB_BRANCH, or HEAD and then used to generate client source. (Sources: 4023, 32645, 32357)
Discovery and timeline
The advisory entries for this vulnerability were published on 2026-10-09 in multiple databases. See the referenced advisories for publication timestamps. (Sources: 4023, 32645, 32357)
Affected versions
According to the advisories, @tinacms/cli is affected from the initial published package (introduced at "0") and the issue is fixed in 3.0.0. One advisory lists the affected range as "<= 2.7.0". (Sources: 4023, 32645)
Fixes and mitigation
A fix is available: the advisories report the issue is fixed in 3.0.0. The sources do not list additional vendor workarounds in the advisory entries. (Sources: 4023, 32645)
Recommended action
Update @tinacms/cli to 3.0.0, as reported in the advisories. Review build-time permissions and environment variables used during preview builds until you can apply the update. (Sources: 4023, 32645)
PatchBriefing score
4.7 / 10 · Medium
Official CVSS: 8.2
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Why this score
The advisory lists a CVSS v3.1 base score of 8.2 (CVSS vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N). The score reflects a network-accessible issue that requires low privileges but can cause high confidentiality and integrity impact. The PatchWire score incorporates this CVSS base score plus modifiers: no known exploitation and no public exploit were reported, and no user interaction is required. (Sources: 32357, 4023)
Affected versions
- @tinacms/cli ≥ 0 < 3.0.0
- vulnerable
- @tinacms/cli <= 2.7.0
- vulnerable
- ≥ 3.0.0
- patched
Reported fixes
A fix is available: the advisories report the issue is fixed in 3.0.0. The sources do not list additional vendor workarounds in the advisory entries. (Sources: 4023, 32645)
How this was built
3 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
NVD (NIST) database
-
GitHub Advisory Database database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email