Injection Vulnerability in Tina CMS by TinaCMS Inc.
CVE-2026-108259

8.2HIGH

Key Information:

Vendor

Tinacms

Vendor
CVE Published:
9 October 2026

What is CVE-2026-108259?

Tina CMS, a headless content management system, is susceptible to a code injection vulnerability that arises when Git branch values are improperly handled. Relying on raw values extracted from environment variables such as VERCEL_GIT_COMMIT_REF and GITHUB_BRANCH, the affected versions prior to 3.0.0 permit crafted branch names to terminate JavaScript string literals. This allows malicious actors to inject executable code during the preview build process, which can run with the privileges of the build process. The injected code is particularly dangerous as it can access sensitive environment credentials, alter deployment artifacts, or initiate unauthorized network requests. Users are strongly encouraged to upgrade to version 3.0.0 or later to mitigate this risk.

Affected Version(s)

cli < 3.0.0

tinacms < 3.0.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.