AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-108260.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 7.6CVSS 3.1 · security-advisories@github.com
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSReceivedModified Oct 09, 2026

Disclosure summary

Tina is a headless content management system. Prior to 0.2.1, the tina-markdown element in packages/@tinacms/web-components/src/tina-markdown.js assigns a rich-text node.url value directly to an anchor href without validating the URL scheme. A content author can store a link using a script-capable scheme, and a visitor who clicks the rendered link executes attacker-controlled script in the site's origin. The script can access same-origin application data and, when the visitor is an editor or administrator, may expose credentials stored by the TinaCMS admin on that origin. This issue is fixed in version 0.2.1.

Source-reported weakness categories

CWE-79, CWE-83

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2026-108260

Open original source · Updated Oct 09, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

GitHub Reviewed Security Advisories · GHSA-c42q-qvc3-j6vg

Open original source · Updated Oct 09, 2026

@tinacms/web-components: `tina-markdown` writes rich-text link URLs into `href` without scheme validation, allowing stored XSS

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
npm@tinacms/web-components0.2.1

Original records & references

PUBLISHED 2026-10-09T17:17:04-04:00
MODIFIED 2026-10-09T17:17:04-04:00
INGESTED 2026-10-10T20:55:12-04:00