CVE-2026-108261 - TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment
CVE ID :CVE-2026-108261 Published : Oct. 9, 2026, 8:43 p.m. | 46 minutes ago Description :Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled...