Vulnerability GHSA-529f-9qwm-9628
High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
9 months ago
December 18, 2025 at 06:45 PM UTC
tinacms is vulnerable to arbitrary code execution
0.0.0-202231073 - 3.1.0
0.0.0-202231073 - 3.1.0
Summary
tinacms is vulnerable to arbitrary code execution
Details
Summary
tinacms uses the gray-matter package in an insecure way allowing attackers that can control the content of the processed markdown files, e.g., blog posts, to execute arbitrary code.
Details
The gray-matter package executes by default the code in the markdown file's front matter. tinacms does not change this behavior when process markdown file, e.g., by passing a custom engine property for js/javascript in the options object.
PoC
- Create a tinacms app using the cli/documentation:
npx create-tina-app@latest
- Modify one of the blog posts to contain the following front matter:
---js
{
"title": "Pawned" + console.log(require("fs").readFileSync("/etc/passwd").toString())
}
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
3 hours ago
Tina: Code injection via unescaped Git branch name in generated client source
0.0.0-202231073 - 2.7.0 GHSA-pwhx-cvv3-qj5c
0.0.0-202231073 - 2.7.0 GHSA-pwhx-cvv3-qj5c
Critical
3 hours ago
TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment
0.0.0-202231073 - 3.13.0 GHSA-x34j-47hf-4xg7
0.0.0-202231073 - 3.13.0 GHSA-x34j-47hf-4xg7
Medium Risk
1 month ago
Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root
0.0.0-202231073 - 2.5.1 GHSA-rgr9-r7mj-mf6x
0.0.0-202231073 - 2.5.1 GHSA-rgr9-r7mj-mf6x
High Risk
3 months ago
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
0.0.0-202231073 - 3.9.2 GHSA-g5qx-h5f3-mp2f
0.0.0-202231073 - 3.9.2 GHSA-g5qx-h5f3-mp2f
High Risk
3 months ago
@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels
0.0.0-202231073 - 2.4.2 GHSA-4936-9hrh-qqpw
0.0.0-202231073 - 2.4.2 GHSA-4936-9hrh-qqpw
Impacted packages
Timeline
Published
9 months ago
December 18, 2025 at 06:45 PM UTC
Fixed (2.0.3)
9 months ago
December 18, 2025 at 02:17 AM UTC
Fixed (3.1.1)
9 months ago
December 18, 2025 at 02:17 AM UTC
Fixed (2.0.4)
9 months ago
December 18, 2025 at 02:18 AM UTC
Last Modified
9 months ago
December 18, 2025 at 09:26 PM UTC