{"id":"GHSA-g5qx-h5f3-mp2f","summary":"TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover","details":"TinaCMS registers window message listeners — the useTina overlay handler, the OAuth authentication popup handler, and the admin↔preview iframe GraphQL reducer — that act on event.data without verifying event.origin or event.source, and post messages using non-specific target origins. A page the victim visits (or a window in an opener/iframe relationship with a Tina admin) can forge messages to drive the editor, inject preview content, or observe/forge the OAuth popup channel to take over an authenticated editing session.\n\nFixed in [#7056](https://github.com/tinacms/tinacms/pull/7056) by allow-listing trusted origins and verifying event.source (isFromAdmin, isFromTrustedPreviewOrigin), and by posting only to explicit target origins (never \"*\").\n\nNote: the rich-text URL-sanitization issue previously bundled here has been split into its own advisory (GHSA-2vcc-5v34-9jc8) so each vulnerability can receive a distinct CVE.","aliases":["CVE-2026-55660"],"modified":"2026-09-10T03:50:49.428018311Z","published":"2026-06-19T21:15:29Z","database_specific":{"github_reviewed_at":"2026-06-19T21:15:29Z","nvd_published_at":null,"cwe_ids":["CWE-346","CWE-601","CWE-79","CWE-940"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/tinacms/tinacms/security/advisories/GHSA-g5qx-h5f3-mp2f"},{"type":"WEB","url":"https://github.com/tinacms/tinacms/pull/7056"},{"type":"PACKAGE","url":"https://github.com/tinacms/tinacms"}],"affected":[{"package":{"name":"tinacms","ecosystem":"npm","purl":"pkg:npm/tinacms"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.9.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-g5qx-h5f3-mp2f/GHSA-g5qx-h5f3-mp2f.json"}},{"package":{"name":"@tinacms/app","ecosystem":"npm","purl":"pkg:npm/%40tinacms/app"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.5.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-g5qx-h5f3-mp2f/GHSA-g5qx-h5f3-mp2f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}