Description
Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL through packages/@tinacms/app/src/preview.tsx, while packages/@tinacms/app/src/lib/preview-origin.ts derives expectedOrigin from that same URL for the GraphQL message channel in packages/@tinacms/app/src/lib/graphql-reducer.ts. An unauthenticated attacker can send a crafted link to a signed-in editor, cause the admin to frame an attacker origin, and have that frame treated as the trusted preview. The attacker-controlled frame can submit GraphQL reads or mutations that the admin executes with the editor credentials, exposing or modifying protected content. This issue is fixed in tinacms 3.14.0 and @tinacms/app 2.5.14.
Published: 2026-10-09
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to embed an iframe that points to an attacker-controlled origin within the TinaCMS administrator preview. Because the embedding logic incorrectly trusts the iframe’s origin, the attacker can submit GraphQL queries and mutations through the preview channel as if they were performed by an authenticated editor, exposing or altering protected content.

Affected Systems

All instances of TinaCMS using tinacms versions earlier than 3.14.0 or @tinacms/app earlier than 2.5.14 are affected. Any deployment that still hosts the /~/* admin preview route with the legacy preview implementation is vulnerable.

Risk and Exploitability

The vulnerability is scored CVSS 9.3, indicating a critical impact. The exploitable vector is a web‑based attack where the attacker sends a crafted link to a logged‑in editor, triggering the malicious iframe. Because the exploit requires an authenticated editor session to be tricked, it is a targeted attack. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high CVSS suggests that once discovered, attackers could abuse it to read or modify content with editor privileges.

Generated by OpenCVE AI on October 9, 2026 at 22:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade TinaCMS to version 3.14.0 or @tinacms/app 2.5.14 or later to apply the official security fix.
  • Verify that the upgrade has replaced the admin preview route and preview‑origin code; ensure that the preview iframe enforces same‑origin checks before accepting GraphQL messages.
  • For environments that cannot upgrade immediately, limit editor access to the admin preview route or block external URLs from being loaded in iframes to mitigate potential misuse.

Generated by OpenCVE AI on October 9, 2026 at 22:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-x34j-47hf-4xg7 TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment
History

Fri, 09 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL through packages/@tinacms/app/src/preview.tsx, while packages/@tinacms/app/src/lib/preview-origin.ts derives expectedOrigin from that same URL for the GraphQL message channel in packages/@tinacms/app/src/lib/graphql-reducer.ts. An unauthenticated attacker can send a crafted link to a signed-in editor, cause the admin to frame an attacker origin, and have that frame treated as the trusted preview. The attacker-controlled frame can submit GraphQL reads or mutations that the admin executes with the editor credentials, exposing or modifying protected content. This issue is fixed in tinacms 3.14.0 and @tinacms/app 2.5.14.
Title TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment
Weaknesses CWE-346
CWE-441
CWE-601
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T20:43:37.580Z

Reserved: 2026-10-09T17:33:15.410Z

Link: CVE-2026-108261

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T21:17:04.347

Modified: 2026-10-09T21:17:04.347

Link: CVE-2026-108261

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T22:30:13Z

Weaknesses
  • CWE-346

    Origin Validation Error

  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')