{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/tinacms-cli--2.7.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:tinacms:cli:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-108259"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TinaCMS CLI (\u003c= 2.7.0)"],"_cs_severities":["high"],"_cs_tags":["supply-chain","code-injection","ci-cd","rce"],"_cs_type":"advisory","_cs_vendors":["TinaCMS"],"content_html":"\u003cp\u003eThe TinaCMS CLI (up to version 2.7.0) contains a code injection vulnerability arising from the unsafe handling of Git branch names during the generation of client source code. The package reads environment variables like \u003ccode\u003eVERCEL_GIT_COMMIT_REF\u003c/code\u003e or \u003ccode\u003eGITHUB_BRANCH\u003c/code\u003e and incorporates the raw string into the generated \u003ccode\u003eclient.ts\u003c/code\u003e file without any sanitization or encoding. Because the resulting string is placed inside a single-quoted JavaScript template, an attacker can use a Git branch name containing single quotes and JavaScript syntax to escape the string literal and execute arbitrary code. This execution occurs during the build process of consumer projects, such as preview deployments in CI/CD pipelines, granting the attacker access to build-time environment variables, credentials, and the ability to modify build artifacts.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target repository using an affected version of \u003ccode\u003etinacms/cli\u003c/code\u003e for their build pipeline.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a pull request or creates a branch in the target repository.\u003c/li\u003e\n\u003cli\u003eAttacker names the Git branch with a malicious payload (e.g., \u003ccode\u003ex'+(globalThis.__TINA_PROBE='hit')+'\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe victim's CI/CD platform (e.g., Vercel, GitHub Actions) triggers an automated build for the new branch.\u003c/li\u003e\n\u003cli\u003eThe TinaCMS CLI codegen process reads the malicious branch name from the environment.\u003c/li\u003e\n\u003cli\u003eThe CLI concatenates the payload into the \u003ccode\u003eclient.ts\u003c/code\u003e template and writes it to the local file system.\u003c/li\u003e\n\u003cli\u003eThe CI build process runs a bundler (e.g., esbuild) which parses and evaluates the injected JavaScript code.\u003c/li\u003e\n\u003cli\u003eThe injected expression executes within the build environment, potentially leaking secrets or altering the final deployment artifact.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary code execution within the build environment. This poses a significant risk to CI/CD pipelines by potentially exposing \u003ccode\u003eNPM_TOKEN\u003c/code\u003e, \u003ccode\u003eVERCEL_TOKEN\u003c/code\u003e, cloud API keys, and other build-time secrets. Furthermore, attackers can modify build artifacts to inject malicious code into the final production output, leading to downstream supply-chain compromises for users of the deployed application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@tinacms/cli\u003c/code\u003e to a version that properly sanitizes branch input or migrates runtime configuration to JSON files as recommended by the vendor.\u003c/li\u003e\n\u003cli\u003eAudit CI/CD logs for build-time errors occurring during the codegen phase, as malformed branch names may cause unexpected build failures.\u003c/li\u003e\n\u003cli\u003eReview CI/CD environment configurations to minimize the exposure of sensitive tokens and secrets during preview deployments, which are most vulnerable to this attack vector.\u003c/li\u003e\n\u003cli\u003ePatch CVE-2026-108259 immediately by updating the affected \u003ccode\u003e@tinacms/cli\u003c/code\u003e package in \u003ccode\u003epackage.json\u003c/code\u003e.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-09T21:24:01Z","date_published":"2026-10-09T21:24:01Z","id":"https://feed.craftedsignal.io/briefs/2026-10-tina-cli-code-injection/","summary":"The TinaCMS CLI package fails to sanitize Git branch names during client code generation, allowing an attacker to inject and execute arbitrary JavaScript expressions within consumer build environments.","title":"TinaCMS CLI Arbitrary Code Execution via Git Branch Name Injection","url":"https://feed.craftedsignal.io/briefs/2026-10-tina-cli-code-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - TinaCMS CLI (\u003c= 2.7.0)","version":"https://jsonfeed.org/version/1.1"}