CVE WATCH / VULNERABILITY DETAIL

CVE-2026-108261

CRITICALCVSS 9.3NVD feed

Published 9 October 2026 · tracked since 10 October 2026

Description

Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL through packages/@tinacms/app/src/preview.tsx, while pac

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-108261 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-108261

CRITICALCVSS 9.3NVD feed

Published 9 October 2026 · tracked since 10 October 2026

Description

Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL through packages/@tinacms/app/src/preview.tsx, while pac

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]