MEDIUMnpm
GHSA-2vcc-5v34-9jc8· CVE-2026-55661TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
Modified: 9/10/2026
package
pkg:npm/tinacms
TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
Modified: 9/10/2026
tinacms is vulnerable to arbitrary code execution
Modified: 12/18/2025
Tina: Path Traversal in Media Upload Handle
Modified: 3/14/2026
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
Modified: 9/10/2026