Vulnerability in Tina CMS Affects Markdown Component Security
CVE-2026-108260
7.6HIGH
What is CVE-2026-108260?
The Tina content management system, prior to version 0.2.1, contains a vulnerability in the tina-markdown element where URLs can be assigned without proper validation of their scheme. This flaw allows a content author to use a malicious script-capable link. When users, particularly those with editor or administrator privileges, click on such links, they may inadvertently execute attacker-controlled scripts within the context of the site. Consequently, this could lead to unauthorized access to sensitive application data or credentials associated with the TinaCMS administration interface. The issue has been addressed in version 0.2.1, where URL validation was implemented to mitigate the risks.
Affected Version(s)
tinacms < 3.14.0
web-components < 0.2.1
