← Späť na vyhľadávanie CVE

CVE-2026-54074

Tina

Popis

Tina is a headless content management system. @tinacms/cli versions prior to 2.4.3 contain a Remote Code Execution vulnerability in the Forestry-to-Tina migration command. The internal helper addVariablesToCode unquotes any value matching the marker -__TINA_INTERNAL__:::(.*?):::- inside the stringified collection JSON. User-supplied label and name fields from .forestry/**/*.yml are placed into that JSON without any sanitisation. An attacker who controls a Forestry-style project can therefore inject arbitrary JavaScript into the generated tina/templates.{ts,js} file. The injected code is written at module top level, so it executes the moment the developer runs tinacms dev or tinacms build, with the developer-s privileges. This issue has been fixed in version 2.4.3.

CVSS 7.8EPSS 0.16999999999999998%Riziko 0.79
Zobraziť zdroj
Zverejnené
2026-07-01 21:17:03
Dotknuté verzie
<2.4.3
Typ
Kritický softvér
Vektor
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H