Impact
Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross‑origin postMessage handlers and a rich‑text URL‑sanitization bypass enable stored XSS and session takeover. The library registers window message listeners— the useTina overlay handler, the OAuth authentication popup handler, and the admin↔preview iframe GraphQL reducer—that act on event.data without verifying event.origin or event.source and post messages using non‑specific target origins, while insufficient URL sanitization in rich‑text content allows malicious URLs to persist and execute. A page the victim visits (or a window in an opener/iframe relationship with a Tina admin) can forge messages to drive the editor, inject preview content, or observe/forge the OAuth popup channel to take over an authenticated editing session. This issue has been fixed in versions @tinacms/app 2.5.6 and tinacms 3.9.3.
Affected Systems
The affected products are the TinaCMS libraries @tinacms/app and tinacms. All releases before @tinacms/app 2.5.6 and tinacms 3.9.3 are vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 7.6, indicating a high impact if exploited. The EPSS score is < 1%, which indicates a very low but non‑zero probability of exploitation. The issue has not been listed in CISA’s KEV catalog, suggesting it is not a known widespread exploit at the time of analysis. The likely attack vector is a malicious site or a page in an opener/iframe relationship that can forge messages to the Tina editor, inject malicious URL content, or hijack the OAuth authentication flow, resulting in arbitrary code execution in the user’s browser context editing sessions.
OpenCVE Enrichment
Github GHSA