Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x34j-47hf-4xg7 | TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment |
Fri, 09 Oct 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL through packages/@tinacms/app/src/preview.tsx, while packages/@tinacms/app/src/lib/preview-origin.ts derives expectedOrigin from that same URL for the GraphQL message channel in packages/@tinacms/app/src/lib/graphql-reducer.ts. An unauthenticated attacker can send a crafted link to a signed-in editor, cause the admin to frame an attacker origin, and have that frame treated as the trusted preview. The attacker-controlled frame can submit GraphQL reads or mutations that the admin executes with the editor credentials, exposing or modifying protected content. This issue is fixed in tinacms 3.14.0 and @tinacms/app 2.5.14. | |
| Title | TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment | |
| Weaknesses | CWE-346 CWE-441 CWE-601 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T20:43:37.580Z
Reserved: 2026-10-09T17:33:15.410Z
Link: CVE-2026-108261
No data.
Status : Received
Published: 2026-10-09T21:17:04.347
Modified: 2026-10-09T21:17:04.347
Link: CVE-2026-108261
No data.
OpenCVE Enrichment
Updated: 2026-10-09T22:30:13Z
Github GHSA