CVE-2025-68278: tinacms is vulnerable to arbitrary code execution
tinacms uses the gray-matter package in an insecure way allowing attackers that can control the content of the processed markdown files, e.g., blog posts, to execute arbitrary code.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-68278 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →