{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/web-components/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:tinacms:web-components:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.6,"id":"CVE-2026-108260"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@tinacms/web-components (\u003c= 0.2.0)"],"_cs_severities":["high"],"_cs_tags":["xss","web-components","tinacms"],"_cs_type":"advisory","_cs_vendors":["TinaCMS"],"content_html":"\u003cp\u003eThe \u003ccode\u003e@tinacms/web-components\u003c/code\u003e package (specifically version 0.2.0 and earlier) contains a high-severity stored Cross-Site Scripting (XSS) vulnerability. The \u003ccode\u003e\u0026lt;tina-markdown\u0026gt;\u003c/code\u003e component is responsible for rendering rich-text content from the TinaCMS content API into the DOM. While other renderers in the TinaCMS ecosystem correctly sanitize URL attributes, this specific component directly assigns the \u003ccode\u003eurl\u003c/code\u003e property of link nodes to the \u003ccode\u003ehref\u003c/code\u003e attribute of an \u003ccode\u003e\u0026lt;a\u0026gt;\u003c/code\u003e element without any scheme validation.\u003c/p\u003e\n\u003cp\u003eAn attacker with the ability to edit content within the CMS can supply a \u003ccode\u003ejavascript:\u003c/code\u003e pseudo-protocol URL. When a user clicks the resulting link on the published site, the malicious payload executes in the site's origin. This is particularly dangerous as it allows for the theft of sensitive data, such as local storage tokens (e.g., \u003ccode\u003etinacms-auth\u003c/code\u003e), if the victim is an authenticated editor or administrator.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains access to the TinaCMS administrative interface to edit content fields.\u003c/li\u003e\n\u003cli\u003eAttacker modifies a rich-text field to include a hyperlink targeting a \u003ccode\u003ejavascript:\u003c/code\u003e URI.\u003c/li\u003e\n\u003cli\u003eThe CMS processes and stores the malicious AST representation of the rich-text.\u003c/li\u003e\n\u003cli\u003eThe victim visits the public-facing webpage that utilizes the \u003ccode\u003e\u0026lt;tina-markdown\u0026gt;\u003c/code\u003e web component.\u003c/li\u003e\n\u003cli\u003eThe component renders the malicious AST, creating an \u003ccode\u003e\u0026lt;a\u0026gt;\u003c/code\u003e element with the unvalidated \u003ccode\u003ejavascript:\u003c/code\u003e payload in the \u003ccode\u003ehref\u003c/code\u003e attribute.\u003c/li\u003e\n\u003cli\u003eThe victim clicks the hyperlink.\u003c/li\u003e\n\u003cli\u003eThe browser executes the JavaScript payload in the site's origin.\u003c/li\u003e\n\u003cli\u003eAttacker script exfiltrates sensitive browser data, such as \u003ccode\u003elocalStorage\u003c/code\u003e authentication tokens.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the execution of arbitrary JavaScript in the context of the vulnerable site's origin. Impacted sectors include any organization using TinaCMS for web content management. If an authenticated administrator or editor interacts with the malicious link, the attacker can hijack the session, exfiltrate sensitive local storage data, or perform unauthorized actions on behalf of the user, potentially leading to a full account takeover of the CMS instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@tinacms/web-components\u003c/code\u003e to a patched version once available that implements URL scheme sanitization.\u003c/li\u003e\n\u003cli\u003eUntil a patch is applied, implement a Content Security Policy (CSP) that restricts the usage of \u003ccode\u003ejavascript:\u003c/code\u003e URIs in navigation and forbids inline script execution.\u003c/li\u003e\n\u003cli\u003eUtilize the existing \u003ccode\u003esanitizeUrl\u003c/code\u003e utility from \u003ccode\u003e@tinacms/mdx/sanitize-url\u003c/code\u003e to manually sanitize \u003ccode\u003enode.url\u003c/code\u003e before assignment if patching the library source directly is required.\u003c/li\u003e\n\u003cli\u003eReview content stored in CMS rich-text fields for suspicious \u003ccode\u003ejavascript:\u003c/code\u003e schemes.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-09T21:24:11Z","date_published":"2026-10-09T21:24:11Z","id":"https://feed.craftedsignal.io/briefs/2026-10-tinacms-xss/","summary":"The @tinacms/web-components package is vulnerable to stored Cross-Site Scripting (XSS) due to a failure to validate URL schemes in the tina-markdown component, allowing attackers to execute arbitrary code in the browser context of site visitors.","title":"Stored XSS via Unvalidated URL Scheme in @tinacms/web-components","url":"https://feed.craftedsignal.io/briefs/2026-10-tinacms-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Web-Components","version":"https://jsonfeed.org/version/1.1"}