CVE-2026-108260: CVE-2026-108260: Stored Cross-Site Scripting (XSS) in @tinacms/web-components
CVE-2026-108260: Stored Cross-Site Scripting (XSS) in @tinacms/web-components Vulnerability ID: CVE-2026-108260 CVSS Score: 7.6 Published: 2026-10-09 A Stored Cross-Site Scripting vulnerability in @tinacms/web-compo
CVE-2026-108260: Stored Cross-Site Scripting (XSS) in @tinacms/web-components
Vulnerability ID: CVE-2026-108260
CVSS Score: 7.6
Published: 2026-10-09
A Stored Cross-Site Scripting vulnerability in @tinacms/web-components prior to version 0.2.1 allows low-privileged content authors to execute arbitrary JavaScript code in the context of website visitors via unsanitized URL attributes in custom Markdown rendering components.
TL;DR
Unsanitized link and image URLs in @tinacms/web-components allow content editors to inject stored cross-site scripting payloads via javascript: URIs.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-79 / CWE-83
- Attack Vector: Network (HTTP/HTTPS)
- CVSS v3.1 Score: 7.6 (High)
- Privileges Required: Low (Author / Editor)
- User Interaction: Required (Clicking link)
- Exploit Status: Proof of Concept
- KEV Status: Not Listed
Affected Systems
- @tinacms/web-components < 0.2.1
- tinacms < 3.14.0
-
@tinacms/web-components: < 0.2.1 (Fixed in:
0.2.1) -
tinacms: < 3.14.0 (Fixed in:
3.14.0)
Code Analysis
Commit: 5295e07
Sanitize URL attributes in tina-markdown web component renderer
Exploit Details
- GitHub Security Advisory: Proof of concept markdown AST payload and advisory details
Mitigation Strategies
- Upgrade @tinacms/web-components to version 0.2.1 or higher.
- Upgrade the core tinacms package to version 3.14.0 or higher in monorepo installations.
- Enforce a restrictive Content Security Policy (CSP) blocking inline script execution and unsafe inline URIs.
Remediation Steps:
- Run 'npm install @tinacms/[email protected]' across application packages.
- Verify dependency tree lockfiles to ensure no transitive references to vulnerable component versions remain.
- Rebuild client static assets and deploy updated production bundles.
- Audit CMS datastores for existing stored Markdown elements containing untrusted URL schemes.
References
- GitHub Security Advisory GHSA-c42q-qvc3-j6vg
- Fix Commit 5295e077f0d279c35686a0e481a15e33a4877e3b
- Pull Request #7523
- Release Tag @tinacms/[email protected]
- NVD Vulnerability Detail - CVE-2026-108260
- CVE Record - CVE-2026-108260
Read the full report for CVE-2026-108260 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.