tinacms
13 known vulnerabilities · 0 critical · 4 high
TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
TinaCMS CLI Dev Server Vulnerable to Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS
TinaCMS Vulnerable to Path Traversal Leading to Arbitrary File Read, Write and Delete
@tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions
@tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions
TinaCMS CLI has Arbitrary File Read via Disabled Vite Filesystem Restriction
@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files
@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels