DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-108260: CVE-2026-108260: Stored Cross-Site Scripting (XSS) in @tinacms/web-components

CVE-2026-108260: Stored Cross-Site Scripting (XSS) in @tinacms/web-components

Vulnerability ID: CVE-2026-108260
CVSS Score: 7.6
Published: 2026-10-09

A Stored Cross-Site Scripting vulnerability in @tinacms/web-components prior to version 0.2.1 allows low-privileged content authors to execute arbitrary JavaScript code in the context of website visitors via unsanitized URL attributes in custom Markdown rendering components.

TL;DR

Unsanitized link and image URLs in @tinacms/web-components allow content editors to inject stored cross-site scripting payloads via javascript: URIs.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-79 / CWE-83
  • Attack Vector: Network (HTTP/HTTPS)
  • CVSS v3.1 Score: 7.6 (High)
  • Privileges Required: Low (Author / Editor)
  • User Interaction: Required (Clicking link)
  • Exploit Status: Proof of Concept
  • KEV Status: Not Listed

Affected Systems

  • @tinacms/web-components < 0.2.1
  • tinacms < 3.14.0
  • @tinacms/web-components: < 0.2.1 (Fixed in: 0.2.1)
  • tinacms: < 3.14.0 (Fixed in: 3.14.0)

Code Analysis

Commit: 5295e07

Sanitize URL attributes in tina-markdown web component renderer

Exploit Details

Mitigation Strategies

  • Upgrade @tinacms/web-components to version 0.2.1 or higher.
  • Upgrade the core tinacms package to version 3.14.0 or higher in monorepo installations.
  • Enforce a restrictive Content Security Policy (CSP) blocking inline script execution and unsafe inline URIs.

Remediation Steps:

  1. Run 'npm install @tinacms/web-components@0.2.1' across application packages.
  2. Verify dependency tree lockfiles to ensure no transitive references to vulnerable component versions remain.
  3. Rebuild client static assets and deploy updated production bundles.
  4. Audit CMS datastores for existing stored Markdown elements containing untrusted URL schemes.

References


Read the full report for CVE-2026-108260 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)