Tina: Code injection via unescaped Git branch name in generated client source (CVE-2026-108259)
Description
A code injection vulnerability exists in @tinacms/cli prior to version 3.0.0 where unescaped Git branch names are directly interpolated into generated client source code. This allows an attacker controlling the branch name to inject arbitrary JavaScript expressions that execute during the consumer build process. The vulnerability arises because the branch name is inserted into a string literal without proper escaping or encoding. The impact includes arbitrary code execution with build process privileges, potentially exposing environment variables and enabling supply-chain compromise. A patch is available to fix this issue.
CVSS v3.1
Score 8.2high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
@tinacms/cli versions before 3.0.0 read Git branch names from environment variables such as VERCEL_GIT_COMMIT_REF and directly interpolate them into generated TypeScript client source code without escaping or encoding. This allows a maliciously crafted Git branch name containing characters like single quotes to break out of string literals and inject arbitrary JavaScript expressions. The injected code executes during the build when the generated client module is imported. The vulnerability enables build-time arbitrary code execution with access to environment variables, build artifacts, and network, posing a high risk in environments like Vercel or GitHub Actions preview deployments. The root cause is the lack of JSON serialization or URL encoding of the branch name before insertion into source templates. A fix is available that applies proper serialization and encoding.
Potential Impact
The vulnerability allows an attacker who can create a Git branch or pull request to execute arbitrary code during the build process of a project using @tinacms/cli with preview deployments enabled. This code executes with the privileges of the build environment, potentially exposing sensitive environment variables such as tokens and secrets, modifying build artifacts to compromise the supply chain, and exfiltrating data over the network. While no active exploitation has been reported, the risk is high due to the ability to run arbitrary code in a trusted build context.
Mitigation Recommendations
A patch is available for @tinacms/cli to address this vulnerability. The fix involves properly escaping or encoding the Git branch name before inserting it into generated source code, specifically by using JSON.stringify for serialization and encodeURIComponent for URL components. Users should upgrade to version 3.0.0 or later where this issue is resolved. Until patched, avoid using untrusted branch names in environments that trigger TinaCMS code generation during builds.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-pwhx-cvv3-qj5c
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-108259"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6ac96e3f2cdf04f65689a54c
Added to database: 10/09/2026, 22:44:15 UTC
Last enriched: 10/09/2026, 22:45:55 UTC
Last updated: 10/09/2026, 22:45:55 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.