Injection Vulnerability in Tina CMS by TinaCMS Inc.
CVE-2026-108259
What is CVE-2026-108259?
Tina CMS, a headless content management system, is susceptible to a code injection vulnerability that arises when Git branch values are improperly handled. Relying on raw values extracted from environment variables such as VERCEL_GIT_COMMIT_REF and GITHUB_BRANCH, the affected versions prior to 3.0.0 permit crafted branch names to terminate JavaScript string literals. This allows malicious actors to inject executable code during the preview build process, which can run with the privileges of the build process. The injected code is particularly dangerous as it can access sensitive environment credentials, alter deployment artifacts, or initiate unauthorized network requests. Users are strongly encouraged to upgrade to version 3.0.0 or later to mitigate this risk.
Affected Version(s)
cli < 3.0.0
tinacms < 3.0.0
