PT-2026-50737 · Npm+2 · @Tinacms/Mdx+1

·

CVE-2026-55661

·

Published

2026-06-18

·

Updated

2026-07-06

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions @tinacms/mdx versions prior to 2.1.7 tinacms versions prior to 3.9.3
Description Rich-text parsing and the default link/image renderers fail to sanitize the url field on Slate link/image nodes. This allows content containing javascript: or data:text/html URLs—including versions that use case-variants, whitespace padding, or control-character obfuscation—to be rendered into href or src attributes. Consequently, an actor capable of authoring rich-text content, such as a lower-privileged editor or through imported external content, can execute a stored Cross-Site Scripting (XSS) attack against editors and site viewers.
Recommendations Update @tinacms/mdx to version 2.1.7 or later. Update tinacms to version 3.9.3 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55661
GHSA-2VCC-5V34-9JC8

Affected Products

@Tinacms/Mdx
Tinacms