Vulnerability GHSA-g5qx-h5f3-mp2f

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 19, 2026 at 09:15 PM UTC
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
0.0.0-202231073 - 3.9.2
0.0.0-202231073 - 3.9.2

Summary

TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover

Details

TinaCMS registers window message listeners — the useTina overlay handler, the OAuth authentication popup handler, and the admin↔preview iframe GraphQL reducer — that act on event.data without verifying event.origin or event.source, and post messages using non-specific target origins. A page the victim visits (or a window in an opener/iframe relationship with a Tina admin) can forge messages to drive the editor, inject preview content, or observe/forge the OAuth popup channel to take over an authenticated editing session.

Fixed in #7056 by allow-listing trusted origins and verifying event.source (isFromAdmin, isFromTrustedPreviewOrigin), and by posting only to explicit target origins (never "*").

Note: the rich-text URL-sanitization issue previously bundled here has been split into its own advisory (GHSA-2vcc-5v34-9jc8) so each vulnerability can receive a distinct CVE.

Impacted packages

Timeline

Published
3 months ago
June 19, 2026 at 09:15 PM UTC
Fixed (3.9.3)
3 months ago
June 15, 2026 at 11:34 PM UTC
Fixed (2.5.6)
3 months ago
June 15, 2026 at 11:34 PM UTC
Last Modified
29 days ago
September 10, 2026 at 03:50 AM UTC