Description
uses the package in an insecure way allowing attackers that can control the content of the processed markdown files, e.g., blog posts, to execute arbitrary code.
Recommendation
Update the tinacms package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.1.1
- Patched version(s): 3.1.1
References
Related Issues
- tinacms is vulnerable to arbitrary code execution - CVE-2025-68278
- Joplin is vulnerable to arbitrary code execution - CVE-2022-35131
- Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code - CVE-2023-45133
- Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages - CVE-2025-59417
You might also like:
- Tags:
- npm
- tinacms
Anything's wrong? Let us know Last updated on December 18, 2025


