CVE-2026-108259: Tina: Code injection via unescaped Git branch name in generated client source
@tinacms/cli inserts the raw Git branch value into the generated client.ts source without escaping or encoding. A Git-valid branch name can close the string literal and inject an arbitrary JavaScript expression that executes when the consumer build imports the generated client module.
References
- github.com/advisories/GHSA-pwhx-cvv3-qj5c
- github.com/tinacms/tinacms/commit/d030d414d39e15de79bf36e4c728d57205e71dde
- github.com/tinacms/tinacms/pull/7526
- github.com/tinacms/tinacms/releases/tag/@tinacms/cli@3.0.0
- github.com/tinacms/tinacms/security/advisories/GHSA-pwhx-cvv3-qj5c
- nvd.nist.gov/vuln/detail/CVE-2026-108259
Code Behaviors & Features
Detect and mitigate CVE-2026-108259 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →