{"id":"CVE-2026-55661","aliases":["GHSA-2vcc-5v34-9jc8"],"url":"https://o3.security/vulnerability/CVE-2026-55661","summary":"TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes","details":"Tina is a headless content management system. In versions prior to @tinacms/mdx 2.1.7 and  tinacms 3.9.3,  rich-text parsing and the default link/image renderers did not sanitize the url field on Slate link/image nodes. Content containing javascript: or data:text/html URLs — including case-variant, whitespace-padded, and control-character-obfuscated forms — is rendered into href/src and executes when the content is viewed. Any actor able to author rich-text content (for example a lower-privileged editor, or imported/external content) can achieve stored XSS against editors and site viewers. This issue is fixed in versions @tinacms/mdx 2.1.7 and  tinacms 3.9.3.","published":"2026-07-01T20:44:50.116Z","modified":"2026-08-12T03:51:31.677273490Z","cvss":null,"epss":{"score":0.00405,"percentile":0.33803,"asOf":"2026-09-07"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"tinacms","fixedVersion":"3.9.3"},{"ecosystem":"npm","name":"@tinacms/mdx","fixedVersion":"2.1.7"}],"fix":{"url":"https://github.com/tinacms/tinacms/pull/7056","label":"tinacms/tinacms#7056"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55661.json"},{"type":"ADVISORY","url":"https://github.com/tinacms/tinacms/security/advisories/GHSA-2vcc-5v34-9jc8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55661"},{"type":"FIX","url":"https://github.com/tinacms/tinacms/pull/7056"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:31.677273490Z"}}