CVE-2026-108261: TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment
The TinaCMS admin builds its preview <iframe src> from the /~/* hash-router splat without checking that the value stays same-origin. A fragment with a doubled slash (#/~//attacker.example/p) becomes the protocol-relative URL //attacker.example/p, so the admin frames an external site. That same unvalidated string derives expectedOrigin, the only trust anchor for the admin↔preview postMessage channel, so the attacker’s frame is treated as trusted: it can submit any GraphQL operation, which the admin executes with the signed-in editor’s token and posts back to the attacker’s origin.
One link, opened by a logged-in editor, gives an unauthenticated remote attacker arbitrary read and write access to the site’s content API as that editor.
References
- github.com/advisories/GHSA-x34j-47hf-4xg7
- github.com/tinacms/tinacms/commit/b57dbf4b56201aef15cd92caa49fd12ab96bbecf
- github.com/tinacms/tinacms/pull/7522
- github.com/tinacms/tinacms/releases/tag/@tinacms/app@2.5.14
- github.com/tinacms/tinacms/releases/tag/tinacms@3.14.0
- github.com/tinacms/tinacms/security/advisories/GHSA-x34j-47hf-4xg7
- nvd.nist.gov/vuln/detail/CVE-2026-108261
Code Behaviors & Features
Detect and mitigate CVE-2026-108261 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →