TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment (CVE-2026-108261)
Description
TinaCMS admin interface contains a critical vulnerability (CVE-2026-108261) where the preview iframe source URL is constructed from a URL fragment without proper same-origin validation. This allows an attacker to craft a URL that causes the admin to load an attacker-controlled origin in the iframe, which is then trusted by the admin's postMessage channel. Consequently, an unauthenticated remote attacker can perform arbitrary read and write GraphQL operations on the site's content API with the privileges of a logged-in editor. The vulnerability affects TinaCMS versions prior to 3.14.0 and @tinacms/app versions prior to 2.5.14. A patch is available to fix this issue by normalizing the URL and enforcing same-origin checks.
CVSS v3.1
Score 9.3critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The TinaCMS admin preview iframe source URL is derived from the hash-router splat parameter without enforcing same-origin restrictions. Specifically, a URL fragment with a double slash (e.g., #/~//attacker.example/p) results in a protocol-relative URL (//attacker.example/p) that loads an external attacker-controlled origin in the iframe. The admin uses this same unvalidated URL to compute the expected origin for the postMessage communication channel, causing the attacker-controlled iframe to be trusted. This enables the attacker to submit arbitrary GraphQL operations executed with the signed-in editor's token, granting full read and write access to the content API. The vulnerability arises from the router returning a splat with a leading slash, combined with the lack of iframe sandboxing and absence of Content Security Policy. An incomplete fix in earlier versions added origin checks but did not validate the URL source. The recommended fix is to normalize the splat to a same-origin path and restrict the expected origin to the window's origin. The vulnerability is confirmed in [email protected] and @tinacms/[email protected] and affects all earlier versions up to but not including 3.14.0 and 2.5.14 respectively.
Potential Impact
An unauthenticated remote attacker can craft a URL that, when opened by a logged-in editor, causes the TinaCMS admin to load an attacker-controlled iframe that is trusted by the admin's postMessage channel. This allows the attacker to perform arbitrary GraphQL queries and mutations with the privileges of the signed-in editor, effectively granting full read and write access to the site's content API. This compromises the confidentiality and integrity of the site's content. There is no indication of availability impact. No known exploits in the wild have been reported as of the publication date.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade TinaCMS to version 3.14.0 or later and @tinacms/app to version 2.5.14 or later, which include fixes that normalize the URL fragment to enforce same-origin restrictions and restrict the expected origin to the window's origin. The vulnerability arises from unvalidated URL fragments and lack of iframe sandboxing; the patch addresses these issues. Until patched, avoid opening untrusted URLs in the TinaCMS admin interface. No additional mitigations such as CSP or iframe sandboxing are mentioned as part of the official fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-x34j-47hf-4xg7
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-108261"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6ac96e3f2cdf04f65689a54d
Added to database: 10/09/2026, 22:44:15 UTC
Last enriched: 10/09/2026, 22:46:01 UTC
Last updated: 10/09/2026, 22:46:01 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.