TinaCMS Admin Iframe Origin Validation Bypass
TinaCMS improperly validates admin preview URLs, allowing attackers to frame external origins and hijack the postMessage trust channel to perform unauthorized GraphQL operations.
TinaCMS contains a critical vulnerability where the admin preview feature constructs an <iframe src> attribute from a URL fragment splat without verifying that the destination remains same-origin. By crafting a URL fragment with a doubled slash (e.g., #/~//attacker.example/p), an attacker can force the admin dashboard to embed an external site. Because the application derives its expectedOrigin trust anchor from the same unvalidated input, the attacker-controlled iframe is treated as a trusted peer for the postMessage communication channel.
Once an authenticated editor is lured to a malicious link, the attacker-controlled iframe can intercept the administrative session. The attacker can then inject arbitrary GraphQL queries, which the TinaCMS admin executes using the editor's active session token. The resulting data is then posted back to the attacker's origin, resulting in unauthorized read and write access to the site's content API. This issue affects the tinacms and @tinacms/app packages.
Attack Chain
- Attacker crafts a malicious URL containing a double slash in the hash fragment (
#/~//evil.com/page). - Attacker induces an authenticated TinaCMS editor to click the malicious link.
- The TinaCMS admin
HashRouterinterprets the fragment as a protocol-relative URL and loads//evil.com/pageinto an iframe. - The application logic derives
expectedOriginfrom the same malicious input, incorrectly marking the external origin as trusted. - The attacker-controlled frame sends an
openmessage to the admin via thepostMessagechannel. - The TinaCMS admin validates the message origin against the poisoned
expectedOrigin, confirming it as trusted. - The admin executes the attacker's supplied GraphQL query using the editor's authentication token.
- The admin sends the query result back to the attacker-controlled frame, completing data exfiltration.
Impact
Successful exploitation allows unauthenticated remote attackers to gain full read and write access to the content managed by the TinaCMS instance. As the operations are performed using the authenticated editor's credentials, the attacker can modify site content, delete documents, or retrieve sensitive data exposed through the GraphQL API, effectively bypassing all authentication controls for the CMS content.
Recommendation
Prioritize upgrading TinaCMS and associated packages to a version where this vulnerability is mitigated. Since the source notes that tinacms@3.9.3 hardening was incomplete, audit all instances for any version that does not explicitly enforce a strict same-origin check for the preview iframe. Ensure that getExpectedPreviewOrigin is refactored to refuse any origin other than window.location.origin. Deploy a Content Security Policy (CSP) that restricts frame-src to trusted local origins to mitigate the risk of cross-origin framing.
Immediate actions
Inventory all instances of TinaCMS and apply the latest available patches.
Mitigations
Implement a strict Content Security Policy (CSP) restricting frame-src to same-origin.
Cross-origin framing vulnerability