Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.7 Node.js & npm GHSA-x34j-47hf-4xg7 CVE-2026-108261

CVE-2026-108261 — TinaCMS admin preview can load attacker origin via URL fragment

An origin-validation flaw in TinaCMS admin preview can allow an attacker-controlled origin to be framed and treated as a trusted GraphQL preview, enabling GraphQL reads or mutations using an editor's credentials. (CVE-2026-108261, GHSA-x34j-47hf-4xg7)

Synthesized by AI from 3 sources · updated 1 hour ago

AI summary

TinaCMS contains an origin-validation vulnerability in its admin preview route that can let an attacker-controlled origin be framed and treated as the trusted preview. The issue is tracked as CVE-2026-108261 / GHSA-x34j-47hf-4xg7. Fixed releases are available from the project.

What happened

The admin preview route can turn an attacker-controlled hash-router splat into an off-origin iframe URL and then use that URL to derive the preview's expected origin for the GraphQL message channel. An unauthenticated attacker can send a crafted link to a signed-in editor, cause the admin to frame an attacker origin, and have that frame treated as the trusted preview. The attacker-controlled frame can submit GraphQL reads or mutations that the admin executes with the editor's credentials, exposing or modifying protected content. (Sources: 4022, 32644, 32359)

Technical cause

The vulnerability arises because the admin preview code turns a hash-router splat from the /~/* route into an iframe URL, and the preview-origin logic derives expectedOrigin from that same URL for the GraphQL message channel. That flow permits an attacker-controlled fragment to set an off-origin origin which is then trusted by the GraphQL messaging implementation. (Sources: 4022, 32644)

Why it matters

The issue has a CVSS v3.1 base score of 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N), reflecting remote unauthenticated impact that can cause confidentiality and integrity loss via GraphQL requests executed with an editor session. The advisory's PatchWire score is 5.7; contributing factors include the high CVSS base score and that the vulnerability can be triggered by an unauthenticated remote actor. (Sources: 32359, 4022)

Who is affected

Projects using the tinacms package and the @tinacms/app package in the affected ranges are impacted. The advisory identifies affected ranges and last-affected markers for each package. (Sources: 4022, 32644)

Affected versions

According to the advisory claims: tinacms is affected from 0 up to and including 3.13.0 (fixed in 3.14.0); @tinacms/app is affected from 0 up to and including 2.5.13 (fixed in 2.5.14). (Sources: 4022, 32644)

Fixes and mitigation

The issue is fixed in tinacms 3.14.0 and in @tinacms/app 2.5.14. The advisory records that a vendor fix is available. (Sources: 4022, 32644)

Discovery and timeline

The advisory entries were published on 2026-10-09. OSV.dev and the GitHub Advisory Database list publication at 2026-10-09T20:56:48+02:00, and NVD lists publication at 2026-10-09T21:17:04+02:00. The sources do not provide additional discoverer or exploitation timeline details. (Sources: 4022, 32644, 32359)

Recommended action

Upgrade affected deployments to the fixed releases: tinacms 3.14.0 and @tinacms/app 2.5.14. The advisory indicates a vendor fix is available; the sources do not list alternate mitigations. (Sources: 4022, 32644)

PatchBriefing score

5.7 / 10 · Medium

Official CVSS: 9.3

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Why this score

CVSS v3.1 base score 9.3 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N) indicates a high-severity remote vulnerability with potential for confidentiality and integrity loss. The PatchWire score for prioritization is 5.7; the advisory notes the CVSS contribution and that the flaw can be triggered by an unauthenticated remote actor. (Sources: 32359, 4022)

Affected versions

tinacms ≥ 0 < 3.14.0
vulnerable
tinacms <= 3.13.0
vulnerable
≥ 3.14.0
patched
@tinacms/app ≥ 0 < 2.5.14
vulnerable
@tinacms/app <= 2.5.13
vulnerable
≥ 2.5.14
patched

Reported fixes

The issue is fixed in tinacms 3.14.0 and in @tinacms/app 2.5.14. The advisory records that a vendor fix is available. (Sources: 4022, 32644)

How this was built

3 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • NVD (NIST) database
  • GitHub Advisory Database database
Unified report
CVE-2026-108261 — TinaCMS admin preview can load attacker origin via URL fragment
1 article · 3 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email