Vulnerabilities/

tinacms is vulnerable to arbitrary code execution

Severity:
High

Description

uses the package in an insecure way allowing attackers that can control the content of the processed markdown files, e.g., blog posts, to execute arbitrary code.

Recommendation

Update the @tinacms/graphql package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@tinacms/graphql
Anything's wrong? Let us know Last updated on December 18, 2025