CVE-2026-108261

CVE-2026-108261 published: Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL through packa...

View full NVD advisory → ← Back to CVE watch