<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:tinacms:web-Components:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3atinacmsweb-components/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 21:24:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3atinacmsweb-components/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS via Unvalidated URL Scheme in @tinacms/web-components</title><link>https://feed.craftedsignal.io/briefs/2026-10-tinacms-xss/</link><pubDate>Fri, 09 Oct 2026 21:24:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-tinacms-xss/</guid><description>The @tinacms/web-components package is vulnerable to stored Cross-Site Scripting (XSS) due to a failure to validate URL schemes in the tina-markdown component, allowing attackers to execute arbitrary code in the browser context of site visitors.</description><content:encoded><![CDATA[<p>The <code>@tinacms/web-components</code> package (specifically version 0.2.0 and earlier) contains a high-severity stored Cross-Site Scripting (XSS) vulnerability. The <code>&lt;tina-markdown&gt;</code> component is responsible for rendering rich-text content from the TinaCMS content API into the DOM. While other renderers in the TinaCMS ecosystem correctly sanitize URL attributes, this specific component directly assigns the <code>url</code> property of link nodes to the <code>href</code> attribute of an <code>&lt;a&gt;</code> element without any scheme validation.</p>
<p>An attacker with the ability to edit content within the CMS can supply a <code>javascript:</code> pseudo-protocol URL. When a user clicks the resulting link on the published site, the malicious payload executes in the site's origin. This is particularly dangerous as it allows for the theft of sensitive data, such as local storage tokens (e.g., <code>tinacms-auth</code>), if the victim is an authenticated editor or administrator.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker gains access to the TinaCMS administrative interface to edit content fields.</li>
<li>Attacker modifies a rich-text field to include a hyperlink targeting a <code>javascript:</code> URI.</li>
<li>The CMS processes and stores the malicious AST representation of the rich-text.</li>
<li>The victim visits the public-facing webpage that utilizes the <code>&lt;tina-markdown&gt;</code> web component.</li>
<li>The component renders the malicious AST, creating an <code>&lt;a&gt;</code> element with the unvalidated <code>javascript:</code> payload in the <code>href</code> attribute.</li>
<li>The victim clicks the hyperlink.</li>
<li>The browser executes the JavaScript payload in the site's origin.</li>
<li>Attacker script exfiltrates sensitive browser data, such as <code>localStorage</code> authentication tokens.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the execution of arbitrary JavaScript in the context of the vulnerable site's origin. Impacted sectors include any organization using TinaCMS for web content management. If an authenticated administrator or editor interacts with the malicious link, the attacker can hijack the session, exfiltrate sensitive local storage data, or perform unauthorized actions on behalf of the user, potentially leading to a full account takeover of the CMS instance.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade <code>@tinacms/web-components</code> to a patched version once available that implements URL scheme sanitization.</li>
<li>Until a patch is applied, implement a Content Security Policy (CSP) that restricts the usage of <code>javascript:</code> URIs in navigation and forbids inline script execution.</li>
<li>Utilize the existing <code>sanitizeUrl</code> utility from <code>@tinacms/mdx/sanitize-url</code> to manually sanitize <code>node.url</code> before assignment if patching the library source directly is required.</li>
<li>Review content stored in CMS rich-text fields for suspicious <code>javascript:</code> schemes.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>xss</category><category>web-components</category><category>tinacms</category></item></channel></rss>