CVE-2026-108261: Admin Preview Cross-Origin Bypass and GraphQL Hijacking in TinaCMS
Vulnerability ID: CVE-2026-108261
CVSS Score: 9.3
Published: 2026-10-09
A critical origin validation flaw in TinaCMS admin preview allows unauthenticated attackers to bypass cross-origin postMessage checks and execute unauthorized GraphQL queries and mutations under an authenticated editor's context.
TL;DR
TinaCMS admin preview dynamically loaded external origins from hash routing parameters and trusted postMessage traffic from those origins, allowing remote attackers to run arbitrary GraphQL operations on behalf of logged-in editors.
⚠️ Exploit Status: POC
Technical Details
- CVE ID: CVE-2026-108261
- CWE ID: CWE-346 (Origin Validation Error)
- CVSS v3.1: 9.3 (Critical)
- Attack Vector: Network (Requires User Interaction)
- Impact: Full Administrative GraphQL Read/Write Access
- Exploit Status: Proof of Concept / Public Advisory
- CISA KEV Status: Not Listed
Affected Systems
- tinacms npm package prior to 3.14.0
- @tinacms/app npm package prior to 2.5.14
-
tinacms: < 3.14.0 (Fixed in:
3.14.0) -
@tinacms/app: < 2.5.14 (Fixed in:
2.5.14)
Code Analysis
Commit: b57dbf4
Fix admin preview iframe origin check and path resolution bypasses
Exploit Details
- GitHub Security Advisory: Technical description of preview URL parameter manipulation and origin validation collapse.
Mitigation Strategies
- Upgrade tinacms npm package to version 3.14.0 or higher.
- Upgrade @tinacms/app npm package to version 2.5.14 or higher.
- Enforce static origin validation for postMessage handlers without trusting frame target URLs.
Remediation Steps:
- Run 'npm install tinacms@3.14.0 @tinacms/app@2.5.14' in the project directory.
- Rebuild frontend application assets.
- Deploy patched application build to production.
References
- GHSA-x34j-47hf-4xg7 Security Advisory
- NVD Vulnerability Detail - CVE-2026-108261
- CVE.org Record CVE-2026-108261
Read the full report for CVE-2026-108261 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)