CRITICAL 9.3 CVE-2026-108261 Published 9 Oct 2026

Tina Headless CMS Admin Preview Iframe Trust Flaw

Worried this affects your website?

Tina, a headless content management system, has a cross-origin iframe trust vulnerability in its admin preview route. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route can turn an attacker-controlled hash-router splat into an off-origin iframe URL.

The expected preview origin is derived from that same URL for the GraphQL message channel. An unauthenticated attacker can send a crafted link to a signed-in editor, causing the admin to frame an attacker origin and have that frame treated as the trusted preview.

  • Affected versions: tinacms before ersion 3.14.0, @tinacms/app before ersion 2.5.14
  • Precondition: signed-in editor opens a crafted link
  • Impact: attacker-controlled frame can submit GraphQL reads or mutations with editor credentials, exposing or modifying protected content

This issue is fixed in tinacms 3.14.0 and @tinacms/app ersion 2.5.14.

Reference: CVE-2026-108261 on NVD

← Back to Security News