VYPR

npm package

@tinacms/web-components

pkg:npm/%40tinacms/web-components

Vulnerabilities (1)

  • CVE-2026-108260HigOct 9, 2026
    affected < 0.2.1fixed 0.2.1

    Tina is a headless content management system. Prior to 0.2.1, the tina-markdown element in packages/@tinacms/web-components/src/tina-markdown.js assigns a rich-text node.url value directly to an anchor href without validating the URL scheme. A content author can store a link usin