CVE-2026-55661CWE-79CWE-87

TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes

Medium · published July 1, 2026

CVSS v4.0
4.8
EPSS
0%
Percentile
33.8
In the wild
Unconfirmed
What it is

Tina is a headless content management system. In versions prior to @tinacms/mdx 2.1.7 and tinacms 3.9.3, rich-text parsing and the default link/image renderers did not sanitize the url field on Slate link/image nodes. Content containing javascript: or data:text/html URLs — including case-variant, whitespace-padded, and control-character-obfuscated forms — is rendered into href/src and executes when the content is viewed. Any actor able to author rich-text content (for example a lower-privileged editor, or imported/external content) can achieve stored XSS against editors and site viewers. This issue is fixed in versions @tinacms/mdx 2.1.7 and tinacms 3.9.3.

The record
Technical detail
CVSS v4.0
4.8 · MEDIUM
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
EPSS
0.00405 · 33.8th percentile
Weaknesses
CWE-79 · Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'); CWE-87 · Improper Neutralization of Alternate XSS Syntax
Published
2026-07-01T20:44Z
EPSS history
Timeline
  • 01 JUL 20:44Z
    TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
    cvelistv5