Tina 是一个无头内容管理系统。在 tinacms 3.14.0 和 @tinacms/app 2.5.14 版本之前,packages/tinacms/src/admin/index.tsx 中的 /~/* 管理员预览路由可能会将攻击者控制的 hash-router 通配符路径转换为一个非同源 iframe URL。该 URL 通过 packages/@tinacms/app/src/preview.tsx 传递,并且 packages/@tinacms/app/src/lib/preview-origin.t
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108259 | 8.2 HIGH | Tina: Code injection via unescaped Git branch name in generated client source |
| CVE-2026-108260 | 7.6 HIGH | @tinacms/web-components: `tina-markdown` writes rich-text link URLs into `href` without sc |
No comments yet