Stored XSS via Unvalidated URL Scheme in @tinacms/web-components
The @tinacms/web-components package is vulnerable to stored Cross-Site Scripting (XSS) due to a failure to validate URL schemes in the tina-markdown component, allowing attackers to execute arbitrary code in the browser context of site visitors.
CVE search metadata
CVE search record: CVE-2026-108260. Severity: high. CVSS: 7.6. KEV: no. Product: @tinacms/web-components (<= 0.2.0). Brief: Stored XSS via Unvalidated URL Scheme in @tinacms/web-components. Brief link: https://feed.craftedsignal.io/briefs/2026-10-tinacms-xss/
The @tinacms/web-components package (specifically version 0.2.0 and earlier) contains a high-severity stored Cross-Site Scripting (XSS) vulnerability. The <tina-markdown> component is responsible for rendering rich-text content from the TinaCMS content API into the DOM. While other renderers in the TinaCMS ecosystem correctly sanitize URL attributes, this specific component directly assigns the url property of link nodes to the href attribute of an <a> element without any scheme validation.
An attacker with the ability to edit content within the CMS can supply a javascript: pseudo-protocol URL. When a user clicks the resulting link on the published site, the malicious payload executes in the site's origin. This is particularly dangerous as it allows for the theft of sensitive data, such as local storage tokens (e.g., tinacms-auth), if the victim is an authenticated editor or administrator.
Attack Chain
- Attacker gains access to the TinaCMS administrative interface to edit content fields.
- Attacker modifies a rich-text field to include a hyperlink targeting a
javascript:URI. - The CMS processes and stores the malicious AST representation of the rich-text.
- The victim visits the public-facing webpage that utilizes the
<tina-markdown>web component. - The component renders the malicious AST, creating an
<a>element with the unvalidatedjavascript:payload in thehrefattribute. - The victim clicks the hyperlink.
- The browser executes the JavaScript payload in the site's origin.
- Attacker script exfiltrates sensitive browser data, such as
localStorageauthentication tokens.
Impact
Successful exploitation allows for the execution of arbitrary JavaScript in the context of the vulnerable site's origin. Impacted sectors include any organization using TinaCMS for web content management. If an authenticated administrator or editor interacts with the malicious link, the attacker can hijack the session, exfiltrate sensitive local storage data, or perform unauthorized actions on behalf of the user, potentially leading to a full account takeover of the CMS instance.
Recommendation
- Upgrade
@tinacms/web-componentsto a patched version once available that implements URL scheme sanitization. - Until a patch is applied, implement a Content Security Policy (CSP) that restricts the usage of
javascript:URIs in navigation and forbids inline script execution. - Utilize the existing
sanitizeUrlutility from@tinacms/mdx/sanitize-urlto manually sanitizenode.urlbefore assignment if patching the library source directly is required. - Review content stored in CMS rich-text fields for suspicious
javascript:schemes.
Immediate actions
Upgrade @tinacms/web-components to 0.2.1 or later
Mitigations
Apply strict CSP header to prevent javascript: pseudo-protocol execution
CVE-2026-108260