<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>TinaCMS CLI (&lt;= 2.7.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/tinacms-cli--2.7.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 21:24:01 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/tinacms-cli--2.7.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>TinaCMS CLI Arbitrary Code Execution via Git Branch Name Injection</title><link>https://feed.craftedsignal.io/briefs/2026-10-tina-cli-code-injection/</link><pubDate>Fri, 09 Oct 2026 21:24:01 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-tina-cli-code-injection/</guid><description>The TinaCMS CLI package fails to sanitize Git branch names during client code generation, allowing an attacker to inject and execute arbitrary JavaScript expressions within consumer build environments.</description><content:encoded><![CDATA[<p>The TinaCMS CLI (up to version 2.7.0) contains a code injection vulnerability arising from the unsafe handling of Git branch names during the generation of client source code. The package reads environment variables like <code>VERCEL_GIT_COMMIT_REF</code> or <code>GITHUB_BRANCH</code> and incorporates the raw string into the generated <code>client.ts</code> file without any sanitization or encoding. Because the resulting string is placed inside a single-quoted JavaScript template, an attacker can use a Git branch name containing single quotes and JavaScript syntax to escape the string literal and execute arbitrary code. This execution occurs during the build process of consumer projects, such as preview deployments in CI/CD pipelines, granting the attacker access to build-time environment variables, credentials, and the ability to modify build artifacts.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a target repository using an affected version of <code>tinacms/cli</code> for their build pipeline.</li>
<li>Attacker initiates a pull request or creates a branch in the target repository.</li>
<li>Attacker names the Git branch with a malicious payload (e.g., <code>x'+(globalThis.__TINA_PROBE='hit')+'</code>).</li>
<li>The victim's CI/CD platform (e.g., Vercel, GitHub Actions) triggers an automated build for the new branch.</li>
<li>The TinaCMS CLI codegen process reads the malicious branch name from the environment.</li>
<li>The CLI concatenates the payload into the <code>client.ts</code> template and writes it to the local file system.</li>
<li>The CI build process runs a bundler (e.g., esbuild) which parses and evaluates the injected JavaScript code.</li>
<li>The injected expression executes within the build environment, potentially leaking secrets or altering the final deployment artifact.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in arbitrary code execution within the build environment. This poses a significant risk to CI/CD pipelines by potentially exposing <code>NPM_TOKEN</code>, <code>VERCEL_TOKEN</code>, cloud API keys, and other build-time secrets. Furthermore, attackers can modify build artifacts to inject malicious code into the final production output, leading to downstream supply-chain compromises for users of the deployed application.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade <code>@tinacms/cli</code> to a version that properly sanitizes branch input or migrates runtime configuration to JSON files as recommended by the vendor.</li>
<li>Audit CI/CD logs for build-time errors occurring during the codegen phase, as malformed branch names may cause unexpected build failures.</li>
<li>Review CI/CD environment configurations to minimize the exposure of sensitive tokens and secrets during preview deployments, which are most vulnerable to this attack vector.</li>
<li>Patch CVE-2026-108259 immediately by updating the affected <code>@tinacms/cli</code> package in <code>package.json</code>.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>supply-chain</category><category>code-injection</category><category>ci-cd</category><category>rce</category></item></channel></rss>