Sensitive Information leak via Script File in TinaCMS
CVE-2023-25164
What is CVE-2023-25164?
TinaCMS, a Git-backed headless content management system, has a vulnerability where sensitive values stored in the process.env variable are inadvertently exposed in plaintext within the index.js file. This issue impacts versions of the TinaCMS CLI ranging from 1.0.0 to prior to 1.0.9, specifically affecting websites that store sensitive credentials, such as API keys, as environment variables. Affected users are strongly advised to rotate any exposed sensitive keys and update to the patched version @tinacms/cli@1.0.9 to mitigate any potential risks associated with this vulnerability. No known workarounds exist, making immediate action essential for securing your applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
tinacms >= 1.0.0, < 1.0.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
