CVE-2026-108259

high

Description

Tina is a headless content management system. Prior to 3.0.0, @tinacms/cli reads Git branch values from VERCEL_GIT_COMMIT_REF, GITHUB_BRANCH, or HEAD, incorporates the raw value into the API URL, and interpolates that URL into JavaScript string literals in packages/@tinacms/cli/src/next/codegen/index.ts and packages/@tinacms/cli/src/next/codegen/codegen/plugin.ts. A crafted Git-valid branch name containing a quote can terminate the generated string and inject an expression that executes when the generated client module is imported during a preview build. The injected code runs with the build process privileges and can read environment credentials, modify deployment artifacts, or make network requests. This issue is fixed in version 3.0.0.

References

https://github.com/tinacms/tinacms/security/advisories/GHSA-pwhx-cvv3-qj5c

https://github.com/tinacms/tinacms/releases/tag/@tinacms/[email protected]

https://github.com/tinacms/tinacms/pull/7526

https://github.com/tinacms/tinacms/commit/d030d414d39e15de79bf36e4c728d57205e71dde

Details

Source: Mitre, NVD

Published: 2026-10-09

Updated: 2026-10-09

Risk Information

CVSS v2

Base Score: 6.6

Vector: CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:N

Severity: Medium

CVSS v3

Base Score: 8.2

Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

Severity: High