CVE-2026-108259 - Tina: Code injection via unescaped Git branch name in generated client source
CVE ID :CVE-2026-108259 Published : Oct. 9, 2026, 8:36 p.m. | 53 minutes ago Description :Tina is a headless content management system. Prior to 3.0.0, @tinacms/cli reads Git branch values from VERCEL_GIT_COMMIT_REF, GITHUB_BRANCH, or HEAD, incorporates the raw value into the API URL, and...