SCA: security update for @tinacms/app, tinacms (GHSA-x34j-47hf-4xg7)

critical Tenable Cloud Security Plugin ID 474072

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/*
admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router
splat into an off-origin iframe URL through packages/@tinacms/app/src/preview.tsx, while
packages/@tinacms/app/src/lib/preview-origin.ts derives expectedOrigin from that same URL for the GraphQL
message channel in packages/@tinacms/app/src/lib/graphql-reducer.ts. An unauthenticated attacker can send
a crafted link to a signed-in editor, cause the admin to frame an attacker origin, and have that frame
treated as the trusted preview. The attacker-controlled frame can submit GraphQL reads or mutations that
the admin executes with the editor credentials, exposing or modifying protected content. This issue is
fixed in tinacms 3.14.0 and @tinacms/app 2.5.14. (CVE-2026-108261)

Solution

Update the @tinacms/app library and its related packages to version 2.5.14 or later.

See Also

https://github.com/advisories/GHSA-x34j-47hf-4xg7

Plugin Details

Severity: Critical

ID: 474072

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/10/2026

Updated: 10/10/2026

Risk Information

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-108261

CVSS v3

Risk Factor: Critical

Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/9/2026

Vulnerability Publication Date: 10/9/2026

Reference Information

CVE: CVE-2026-108261