Tina 是一个无头内容管理系统(Headless CMS)。在 0.2.1 版本之前, 文件中的 组件会直接将富文本节点的 值赋给锚点( )标签的 属性,而未对 URL 协议进行验证。内容作者可以存储使用支持脚本执行的协议(如 )的链接,当访客点击该渲染后的链接时,将在站点源上下文中执行攻击者控制的脚本。该脚本可以访问同源的应用程序数据;如果访客是编辑器或管理员,则可能暴露 TinaCMS 管理界面在该源上存储的凭据。此问题已在 0.2.1 版本中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tinacms | tinacms | < 3.14.0 | - |
|
| @tinacms | web-components | < 0.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108261 | 9.3 CRITICAL | TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment |
| CVE-2026-108259 | 8.2 HIGH | Tina: Code injection via unescaped Git branch name in generated client source |
No comments yet