{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/@tinacms/app/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["tinacms","@tinacms/app"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["TinaCMS"],"content_html":"\u003cp\u003eTinaCMS contains a critical vulnerability where the admin preview feature constructs an \u003ccode\u003e\u0026lt;iframe src\u0026gt;\u003c/code\u003e attribute from a URL fragment splat without verifying that the destination remains same-origin. By crafting a URL fragment with a doubled slash (e.g., \u003ccode\u003e#/~//attacker.example/p\u003c/code\u003e), an attacker can force the admin dashboard to embed an external site. Because the application derives its \u003ccode\u003eexpectedOrigin\u003c/code\u003e trust anchor from the same unvalidated input, the attacker-controlled iframe is treated as a trusted peer for the \u003ccode\u003epostMessage\u003c/code\u003e communication channel.\u003c/p\u003e\n\u003cp\u003eOnce an authenticated editor is lured to a malicious link, the attacker-controlled iframe can intercept the administrative session. The attacker can then inject arbitrary GraphQL queries, which the TinaCMS admin executes using the editor's active session token. The resulting data is then posted back to the attacker's origin, resulting in unauthorized read and write access to the site's content API. This issue affects the \u003ccode\u003etinacms\u003c/code\u003e and \u003ccode\u003e@tinacms/app\u003c/code\u003e packages.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts a malicious URL containing a double slash in the hash fragment (\u003ccode\u003e#/~//evil.com/page\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eAttacker induces an authenticated TinaCMS editor to click the malicious link.\u003c/li\u003e\n\u003cli\u003eThe TinaCMS admin \u003ccode\u003eHashRouter\u003c/code\u003e interprets the fragment as a protocol-relative URL and loads \u003ccode\u003e//evil.com/page\u003c/code\u003e into an iframe.\u003c/li\u003e\n\u003cli\u003eThe application logic derives \u003ccode\u003eexpectedOrigin\u003c/code\u003e from the same malicious input, incorrectly marking the external origin as trusted.\u003c/li\u003e\n\u003cli\u003eThe attacker-controlled frame sends an \u003ccode\u003eopen\u003c/code\u003e message to the admin via the \u003ccode\u003epostMessage\u003c/code\u003e channel.\u003c/li\u003e\n\u003cli\u003eThe TinaCMS admin validates the message origin against the poisoned \u003ccode\u003eexpectedOrigin\u003c/code\u003e, confirming it as trusted.\u003c/li\u003e\n\u003cli\u003eThe admin executes the attacker's supplied GraphQL query using the editor's authentication token.\u003c/li\u003e\n\u003cli\u003eThe admin sends the query result back to the attacker-controlled frame, completing data exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to gain full read and write access to the content managed by the TinaCMS instance. As the operations are performed using the authenticated editor's credentials, the attacker can modify site content, delete documents, or retrieve sensitive data exposed through the GraphQL API, effectively bypassing all authentication controls for the CMS content.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize upgrading TinaCMS and associated packages to a version where this vulnerability is mitigated. Since the source notes that \u003ccode\u003etinacms@3.9.3\u003c/code\u003e hardening was incomplete, audit all instances for any version that does not explicitly enforce a strict same-origin check for the preview iframe. Ensure that \u003ccode\u003egetExpectedPreviewOrigin\u003c/code\u003e is refactored to refuse any origin other than \u003ccode\u003ewindow.location.origin\u003c/code\u003e. Deploy a Content Security Policy (CSP) that restricts \u003ccode\u003eframe-src\u003c/code\u003e to trusted local origins to mitigate the risk of cross-origin framing.\u003c/p\u003e\n","date_modified":"2026-10-09T21:23:09Z","date_published":"2026-10-09T21:23:09Z","id":"https://feed.craftedsignal.io/briefs/2026-10-tinacms-iframe-origin-bypass/","summary":"TinaCMS improperly validates admin preview URLs, allowing attackers to frame external origins and hijack the postMessage trust channel to perform unauthorized GraphQL operations.","title":"TinaCMS Admin Iframe Origin Validation Bypass","url":"https://feed.craftedsignal.io/briefs/2026-10-tinacms-iframe-origin-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - @Tinacms/App","version":"https://jsonfeed.org/version/1.1"}