Product
TinaCMS improperly validates admin preview URLs, allowing attackers to frame external origins and hijack the postMessage trust channel to perform unauthorized GraphQL operations.