PT-2026-109316 · Unknown+1 · @Tinacms/App+1

CVE-2026-108261

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions tinacms versions prior to 3.14.0 @tinacms/app versions prior to 2.5.14
Description An origin validation error in the admin preview route allows an unauthenticated attacker to perform a confused-deputy attack against the content API. By sending a crafted link containing a specific hash-router splat to a signed-in editor, an attacker can force the admin interface to frame an external attacker-controlled origin. Because the application derives the expectedOrigin for the GraphQL message channel from this same unvalidated URL, the attacker's frame is treated as a trusted preview.
This allows the attacker-controlled frame to submit arbitrary GraphQL reads or mutations via the open handler in graphql-reducer.ts. These operations are executed by the admin using the signed-in editor's credentials, enabling the attacker to expose or modify protected content. The vulnerability is triggered when a doubled slash in the URL fragment (e.g., #/~//attacker.example/p) is converted into a protocol-relative URL, bypassing intended same-origin restrictions.
Recommendations Update tinacms to version 3.14.0 or later. Update @tinacms/app to version 2.5.14 or later.

Exploit

Fix

Origin Validation Error

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-108261
GHSA-X34J-47HF-4XG7

Affected Products

@Tinacms/App
Tinacms