PT-2026-109316 · Unknown+1 · @Tinacms/App+1
CVE-2026-108261
·
Published
2026-10-09
·
Updated
2026-10-09
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
tinacms versions prior to 3.14.0
@tinacms/app versions prior to 2.5.14
Description
An origin validation error in the admin preview route allows an unauthenticated attacker to perform a confused-deputy attack against the content API. By sending a crafted link containing a specific hash-router splat to a signed-in editor, an attacker can force the admin interface to frame an external attacker-controlled origin. Because the application derives the
expectedOrigin for the GraphQL message channel from this same unvalidated URL, the attacker's frame is treated as a trusted preview.This allows the attacker-controlled frame to submit arbitrary GraphQL reads or mutations via the
open handler in graphql-reducer.ts. These operations are executed by the admin using the signed-in editor's credentials, enabling the attacker to expose or modify protected content. The vulnerability is triggered when a doubled slash in the URL fragment (e.g., #/~//attacker.example/p) is converted into a protocol-relative URL, bypassing intended same-origin restrictions.Recommendations
Update tinacms to version 3.14.0 or later.
Update @tinacms/app to version 2.5.14 or later.
Exploit
Fix
Origin Validation Error
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Tinacms/App
Tinacms