CVE-2026-108260
Received Received - Intake

Stored XSS in Tina CMS via Unsafe URL Scheme in Anchor Tags

Vulnerability report for CVE-2026-108260, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Tina is a headless content management system. Prior to 0.2.1, the tina-markdown element in packages/@tinacms/web-components/src/tina-markdown.js assigns a rich-text node.url value directly to an anchor href without validating the URL scheme. A content author can store a link using a script-capable scheme, and a visitor who clicks the rendered link executes attacker-controlled script in the site's origin. The script can access same-origin application data and, when the visitor is an editor or administrator, may expose credentials stored by the TinaCMS admin on that origin. This issue is fixed in version 0.2.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
tinacms tinacms < 3.14.0
@tinacms web-components < 0.2.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-83 The product does not neutralize or incorrectly neutralizes "javascript:" or other URIs from dangerous attributes within tags, such as onmouseover, onload, onerror, or style.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Tina headless CMS before version 0.2.1. The tina-markdown element allows content authors to set a URL in markdown that uses a script-capable scheme like javascript:. When rendered, clicking the link executes attacker-controlled script in the site's origin. This script can access same-origin application data and, if the visitor is an editor or administrator, may expose credentials stored by the TinaCMS admin.

Detection Guidance

Check if your TinaCMS version is below 0.2.1 by inspecting package.json or running npm list @tinacms/web-components. Look for links with script-capable schemes like javascript: in rendered content.

Impact Analysis

If you use Tina CMS before 0.2.1, attackers could inject malicious scripts via markdown links. Visitors clicking these links may have their data accessed or credentials exposed if they are editors or admins. Regular users might also have their session data compromised.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements. If credentials or personal data are exposed, organizations may face compliance breaches, legal penalties, and reputational damage.

Mitigation Strategies

Upgrade to TinaCMS version 0.2.1 or later immediately. Remove any untrusted content containing script URLs. Restrict admin access to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108260. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart