PT-2026-109315 · Tina · Tina

CVE-2026-108260

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tina versions prior to 0.2.1
Description The tina-markdown element in packages/@tinacms/web-components/src/tina-markdown.js fails to validate the URL scheme when assigning a rich-text node.url value to an anchor href attribute. This allows a content author to store a link using a script-capable scheme, such as javascript:, which is then rendered as a live link. A visitor clicking this link will execute attacker-controlled script within the site's origin. This script can access same-origin application data and potentially expose credentials stored in localStorage under the tinacms-auth key if the visitor is an editor or administrator.
Recommendations Update to version 0.2.1. As a temporary workaround, restrict content authoring permissions to prevent the insertion of unauthorized URL schemes in rich-text fields.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-108260
GHSA-C42Q-QVC3-J6VG

Affected Products

Tina