Medium · 5.7 Node.js & npm GHSA-x34j-47hf-4xg7 CVE-2026-108261
CVE-2026-108261 — TinaCMS admin preview can load attacker origin via URL fragment
An origin-validation flaw in TinaCMS admin preview can allow an attacker-controlled origin to be framed and treated as a trusted GraphQL preview, enabling GraphQL reads or mutations using an editor's credentials. (CVE-2026-108261, GHSA-x34j-47hf-4xg7)
AI summary
TinaCMS contains an origin-validation vulnerability in its admin preview route that can let an attacker-controlled origin be framed and treated as the trusted preview. The issue is tracked as CVE-2026-108261 / GHSA-x34j-47hf-4xg7. Fixed releases are available from the project.
What happened
The admin preview route can turn an attacker-controlled hash-router splat into an off-origin iframe URL and then use that URL to derive the preview's expected origin for the GraphQL message channel. An unauthenticated attacker can send a crafted link to a signed-in editor, cause the admin to frame an attacker origin, and have that frame treated as the trusted preview. The attacker-controlled frame can submit GraphQL reads or mutations that the admin executes with the editor's credentials, exposing or modifying protected content. (Sources: 4022, 32644, 32359)
Technical cause
The vulnerability arises because the admin preview code turns a hash-router splat from the /~/* route into an iframe URL, and the preview-origin logic derives expectedOrigin from that same URL for the GraphQL message channel. That flow permits an attacker-controlled fragment to set an off-origin origin which is then trusted by the GraphQL messaging implementation. (Sources: 4022, 32644)
Why it matters
The issue has a CVSS v3.1 base score of 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N), reflecting remote unauthenticated impact that can cause confidentiality and integrity loss via GraphQL requests executed with an editor session. The advisory's PatchWire score is 5.7; contributing factors include the high CVSS base score and that the vulnerability can be triggered by an unauthenticated remote actor. (Sources: 32359, 4022)
Who is affected
Projects using the tinacms package and the @tinacms/app package in the affected ranges are impacted. The advisory identifies affected ranges and last-affected markers for each package. (Sources: 4022, 32644)
Affected versions
According to the advisory claims: tinacms is affected from 0 up to and including 3.13.0 (fixed in 3.14.0); @tinacms/app is affected from 0 up to and including 2.5.13 (fixed in 2.5.14). (Sources: 4022, 32644)
Fixes and mitigation
The issue is fixed in tinacms 3.14.0 and in @tinacms/app 2.5.14. The advisory records that a vendor fix is available. (Sources: 4022, 32644)
Discovery and timeline
The advisory entries were published on 2026-10-09. OSV.dev and the GitHub Advisory Database list publication at 2026-10-09T20:56:48+02:00, and NVD lists publication at 2026-10-09T21:17:04+02:00. The sources do not provide additional discoverer or exploitation timeline details. (Sources: 4022, 32644, 32359)
Recommended action
Upgrade affected deployments to the fixed releases: tinacms 3.14.0 and @tinacms/app 2.5.14. The advisory indicates a vendor fix is available; the sources do not list alternate mitigations. (Sources: 4022, 32644)
PatchBriefing score
5.7 / 10 · Medium
Official CVSS: 9.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Why this score
CVSS v3.1 base score 9.3 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N) indicates a high-severity remote vulnerability with potential for confidentiality and integrity loss. The PatchWire score for prioritization is 5.7; the advisory notes the CVSS contribution and that the flaw can be triggered by an unauthenticated remote actor. (Sources: 32359, 4022)
Affected versions
- tinacms ≥ 0 < 3.14.0
- vulnerable
- tinacms <= 3.13.0
- vulnerable
- ≥ 3.14.0
- patched
- @tinacms/app ≥ 0 < 2.5.14
- vulnerable
- @tinacms/app <= 2.5.13
- vulnerable
- ≥ 2.5.14
- patched
Reported fixes
The issue is fixed in tinacms 3.14.0 and in @tinacms/app 2.5.14. The advisory records that a vendor fix is available. (Sources: 4022, 32644)
How this was built
3 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
NVD (NIST) database
-
GitHub Advisory Database database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email