VYPR

npm package

@tinacms/app

pkg:npm/%40tinacms/app

Vulnerabilities (1)

  • CVE-2026-108261CriOct 9, 2026
    affected < 2.5.14fixed 2.5.14

    Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL through packages/@tinacms/app/src/pr