Product
The TinaCMS CLI package fails to sanitize Git branch names during client code generation, allowing an attacker to inject and execute arbitrary JavaScript expressions within consumer build environments.