๐Ÿ” CVE Alert

CVE-2026-108259

HIGH 8.2

Tina: Code injection via unescaped Git branch name in generated client source

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

Tina is a headless content management system. Prior to 3.0.0, @tinacms/cli reads Git branch values from VERCEL_GIT_COMMIT_REF, GITHUB_BRANCH, or HEAD, incorporates the raw value into the API URL, and interpolates that URL into JavaScript string literals in packages/@tinacms/cli/src/next/codegen/index.ts and packages/@tinacms/cli/src/next/codegen/codegen/plugin.ts. A crafted Git-valid branch name containing a quote can terminate the generated string and inject an expression that executes when the generated client module is imported during a preview build. The injected code runs with the build process privileges and can read environment credentials, modify deployment artifacts, or make network requests. This issue is fixed in version 3.0.0.

CWE CWE-94
Vendor tinacms
Product tinacms
Published Oct 9, 2026
Last Updated Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for tinacms tinacms

Be the first to know when new high vulnerabilities affecting tinacms tinacms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

tinacms / tinacms
< 3.0.0
@tinacms / cli
< 3.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/tinacms/tinacms/security/advisories/GHSA-pwhx-cvv3-qj5c github.com: https://github.com/tinacms/tinacms/pull/7526 github.com: https://github.com/tinacms/tinacms/commit/d030d414d39e15de79bf36e4c728d57205e71dde github.com: https://github.com/tinacms/tinacms/releases/tag/@tinacms/[email protected]