Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.2 Node.js & npm GHSA-c42q-qvc3-j6vg CVE-2026-108260

CVE-2026-108260: stored XSS in @tinacms/web-components (tina-markdown)

The tina-markdown element in @tinacms/web-components wrote rich-text link URLs into anchor href attributes without validating the URL scheme, allowing stored cross-site scripting. The issue is fixed in 0.2.1. (Sources: OSV, GitHub Advisory, NVD) [4024,32643,32358]

Synthesized by AI from 3 sources · updated 1 hour ago

AI summary

A stored cross-site scripting vulnerability (CWE-79) was reported in the tina-markdown element of @tinacms/web-components. The flaw allows authored content to inject links using script-capable schemes that execute when a visitor clicks the rendered link. A vendor fix is available. [4024,32643,32358]

What happened

The tina-markdown component in @tinacms/web-components assigned a rich-text node.url value directly into an anchor's href attribute without validating the URL scheme. A content author could store a link that uses a script-capable scheme; when a visitor clicks that rendered link, attacker-controlled script runs in the site's origin. [4024,32643,32358]

Technical cause

Improper neutralization of input during web page generation (CWE-79). The code wrote node.url into href without validating or restricting the URL scheme, enabling non-HTTP(s) schemes to execute script in the site's origin. [4024,32643,32358]

Why it matters

Script executed in the site's origin can access same-origin application data. The advisory states that when the visitor is an editor or administrator, the injected script may expose credentials stored by the TinaCMS admin on that origin. This increases the potential impact beyond a typical content-only XSS. [4024,32643,32358]

Who is affected

@tinacms/web-components installations that use the tina-markdown element and render author-supplied rich-text links are affected. The advisory reports the package is affected from initial releases through 0.2.0, with a fix in 0.2.1. [4024,32643,32358]

Discovery and timeline

The advisory entries for this issue were published on 2026-10-09. The OSV and GitHub Advisory entries and the NVD record contain the same vulnerability summary and publication timestamps. No information about an external exploit or an individual discoverer is provided in the sources. [4024,32643,32358]

Affected versions

The advisory lists affected releases from initial releases up through 0.2.0 (<= 0.2.0). The issue is fixed in 0.2.1. [4024,32643,32358]

Fixes and mitigation

A vendor fix is available: the advisory lists 0.2.1 as the fixed release. The published advisories identify the fix version but do not include additional mitigation steps. [4024,32643,32358]

Recommended action

Upgrade @tinacms/web-components to 0.2.1 to apply the vendor fix. Review any authored content that contains links rendered by tina-markdown. The advisories do not provide other vendor-recommended mitigations in the sources. [4024,32643,32358]

PatchBriefing score

4.2 / 10 · Medium

Official CVSS: 7.6

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N

Why this score

The advisory carries a CVSS v3.1 base score of 7.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N) as reported in the sources. The score reflects network attack vector, low attack complexity, required low-level privileges, required user interaction, and high confidentiality impact with partial integrity impact; availability is not affected. Patchwire's composite score for prioritization is 4.2, which incorporates the CVSS base and other factors; the published score factors show no known exploitation or public exploit evidence and no EPS S contribution. [4024,32643,32358]

Affected versions

@tinacms/web-components ≥ 0 < 0.2.1
vulnerable
@tinacms/web-components <= 0.2.0
vulnerable
≥ 0.2.1
patched

Reported fixes

A vendor fix is available: the advisory lists 0.2.1 as the fixed release. The published advisories identify the fix version but do not include additional mitigation steps. [4024,32643,32358]

How this was built

3 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • NVD (NIST) database
  • GitHub Advisory Database database
Unified report
CVE-2026-108260: stored XSS in @tinacms/web-components (tina-markdown)
1 article · 3 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email