Description
uses the package in an insecure way allowing attackers that can control the content of the processed markdown files, e.g., blog posts, to execute arbitrary code.
Recommendation
Update the @tinacms/graphql package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.0.3
- Patched version(s): 2.0.3
References
Related Issues
- tinacms is vulnerable to arbitrary code execution - tinacms - CVE-2025-68278
- Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages - CVE-2025-59417
- React Editable Json Tree vulnerable to arbitrary code execution via function parsing - CVE-2022-36010
- Joplin is vulnerable to arbitrary code execution - CVE-2022-35131
You might also like:
- Tags:
- npm
- @tinacms/graphql
Anything's wrong? Let us know Last updated on December 18, 2025


