Vulnerabilities/

TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes

Severity:
Medium

Description

TinaCMS rich-text parsing and the default link/image renderers did not sanitize the url field on Slate link/image nodes. Content containing javascript: or data:text/html URLs — including case-variant, whitespace-padded, and control-character-obfuscated forms — is rendered into href/src and executes when the content is viewed.

Recommendation

Update the tinacms package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
tinacms
Anything's wrong? Let us know Last updated on June 18, 2026