Vulnerability in Tina CMS Affects Markdown Component Security
CVE-2026-108260

7.6HIGH

Key Information:

Vendor

Tinacms

Vendor
CVE Published:
9 October 2026

What is CVE-2026-108260?

The Tina content management system, prior to version 0.2.1, contains a vulnerability in the tina-markdown element where URLs can be assigned without proper validation of their scheme. This flaw allows a content author to use a malicious script-capable link. When users, particularly those with editor or administrator privileges, click on such links, they may inadvertently execute attacker-controlled scripts within the context of the site. Consequently, this could lead to unauthorized access to sensitive application data or credentials associated with the TinaCMS administration interface. The issue has been addressed in version 0.2.1, where URL validation was implemented to mitigate the risks.

Affected Version(s)

tinacms < 3.14.0

web-components < 0.2.1

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.