Cross-Origin Iframe Vulnerability in Tina CMS by Tina
CVE-2026-108261
9.3CRITICAL
What is CVE-2026-108261?
Tina CMS, a headless content management system, has a vulnerability in its admin preview route that can allow unauthenticated attackers to exploit vulnerabilities linked to frame origins. This flaw occurs prior to versions 3.14.0 and 2.5.14 of Tina CMS and @tinacms/app, where an attacker can craft a URL leading to an off-origin iframe. If a signed-in editor follows this link, the attacker can gain unauthorized access to execute GraphQL operations using the editor's credentials, thereby exposing or altering protected content. This security flaw has been addressed in the latest releases, urging users to upgrade to the fixed versions.
Affected Version(s)
app < 2.5.14
tinacms < 3.14.0
