PT-2026-50737 · Npm+2 · @Tinacms/Mdx+1
CVSS v4.0
4.8
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
@tinacms/mdx versions prior to 2.1.7
tinacms versions prior to 3.9.3
Description
Rich-text parsing and the default link/image renderers fail to sanitize the
url field on Slate link/image nodes. This allows content containing javascript: or data:text/html URLs—including versions that use case-variants, whitespace padding, or control-character obfuscation—to be rendered into href or src attributes. Consequently, an actor capable of authoring rich-text content, such as a lower-privileged editor or through imported external content, can execute a stored Cross-Site Scripting (XSS) attack against editors and site viewers.Recommendations
Update @tinacms/mdx to version 2.1.7 or later.
Update tinacms to version 3.9.3 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Tinacms/Mdx
Tinacms