Vulnerabilities/

TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover

Severity:
High

Description

TinaCMS registers window message listeners — the useTina overlay handler, the OAuth authentication popup handler, and the admin↔preview iframe GraphQL reducer — that act on event.data without verifying event.origin or event.source, and post messages using non-specific target origins.

Recommendation

Update the tinacms package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
tinacms
Anything's wrong? Let us know Last updated on June 19, 2026