DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-108261: CVE-2026-108261: Admin Preview Cross-Origin Bypass and GraphQL Hijacking in TinaCMS

CVE-2026-108261: Admin Preview Cross-Origin Bypass and GraphQL Hijacking in TinaCMS

Vulnerability ID: CVE-2026-108261
CVSS Score: 9.3
Published: 2026-10-09

A critical origin validation flaw in TinaCMS admin preview allows unauthenticated attackers to bypass cross-origin postMessage checks and execute unauthorized GraphQL queries and mutations under an authenticated editor's context.

TL;DR

TinaCMS admin preview dynamically loaded external origins from hash routing parameters and trusted postMessage traffic from those origins, allowing remote attackers to run arbitrary GraphQL operations on behalf of logged-in editors.


⚠️ Exploit Status: POC

Technical Details

  • CVE ID: CVE-2026-108261
  • CWE ID: CWE-346 (Origin Validation Error)
  • CVSS v3.1: 9.3 (Critical)
  • Attack Vector: Network (Requires User Interaction)
  • Impact: Full Administrative GraphQL Read/Write Access
  • Exploit Status: Proof of Concept / Public Advisory
  • CISA KEV Status: Not Listed

Affected Systems

  • tinacms npm package prior to 3.14.0
  • @tinacms/app npm package prior to 2.5.14
  • tinacms: < 3.14.0 (Fixed in: 3.14.0)
  • @tinacms/app: < 2.5.14 (Fixed in: 2.5.14)

Code Analysis

Commit: b57dbf4

Fix admin preview iframe origin check and path resolution bypasses

Exploit Details

Mitigation Strategies

  • Upgrade tinacms npm package to version 3.14.0 or higher.
  • Upgrade @tinacms/app npm package to version 2.5.14 or higher.
  • Enforce static origin validation for postMessage handlers without trusting frame target URLs.

Remediation Steps:

  1. Run 'npm install tinacms@3.14.0 @tinacms/app@2.5.14' in the project directory.
  2. Rebuild frontend application assets.
  3. Deploy patched application build to production.

References


Read the full report for CVE-2026-108261 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)