Impact
The vulnerability is a CWE‑639 Broken Access Control flaw. It occurs when Tina’s isAuthorized function accepts a clientID supplied in the request and validates the bearer token against the TinaCloud application instead of the self‑hosted site's own app. An attacker with a TinaCloud account can use their own app ID and a valid token to trick the backend into treating the attacker as a legitimate user. This allows the attacker to list, read, upload, delete media and, when the TinaCloudBackendAuthProvider is employed, perform GraphQL read, create, update and delete operations on the victim’s content without needing a victim account or interaction.
Affected Systems
Vulnerable products include @tinacms/auth and next-tinacms-azure in the tinacms open‑source framework. Prior to version 1.1.4 of @tinacms/auth and version 15.0.1 of next-tinacms-azure, the buggy logic exists in the source files packages/@tinacms/auth/src/index.ts and packages/next-tinacms-azure/src/auth.ts.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is less than 1%, suggesting a low probability of widespread exploitation at the moment, and the vulnerability is not yet listed in the CISA KEV catalog. However, the flaw permits an attacker to gain full authorisation on the victim site by supplying a malicious clientID, leading to complete compromise of content and media resources if the vulnerable versions are deployed. The attack requires an attacker to possess a TinaCloud account, a valid token, and the ability to send requests to the victim endpoint. The benefit to the attacker is practically total control over the victim's content without direct tenant interaction.
OpenCVE Enrichment
Github GHSA