Impact
The vulnerability allows an unauthenticated attacker to embed an iframe that points to an attacker-controlled origin within the TinaCMS administrator preview. Because the embedding logic incorrectly trusts the iframe’s origin, the attacker can submit GraphQL queries and mutations through the preview channel as if they were performed by an authenticated editor, exposing or altering protected content.
Affected Systems
All instances of TinaCMS using tinacms versions earlier than 3.14.0 or @tinacms/app earlier than 2.5.14 are affected. Any deployment that still hosts the /~/* admin preview route with the legacy preview implementation is vulnerable.
Risk and Exploitability
The vulnerability is scored CVSS 9.3, indicating a critical impact. The exploitable vector is a web‑based attack where the attacker sends a crafted link to a logged‑in editor, triggering the malicious iframe. Because the exploit requires an authenticated editor session to be tricked, it is a targeted attack. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high CVSS suggests that once discovered, attackers could abuse it to read or modify content with editor privileges.
OpenCVE Enrichment
Github GHSA