{"id":"CVE-2026-55661","title":"TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes","summary":"TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes","severity":"medium","cwe":["CWE-79","CWE-87"],"vendor":"tinacms","product":"tinacms","ecosystem":"npm","affected":["tinacms < 3.9.3","@tinacms/mdx < 2.1.7"],"patched":["tinacms 3.9.3","@tinacms/mdx 2.1.7"],"published":"2026-06-18","updated":"2026-06-18","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-2vcc-5v34-9jc8","references":[{"url":"https://github.com/tinacms/tinacms/security/advisories/GHSA-2vcc-5v34-9jc8"},{"url":"https://github.com/tinacms/tinacms/pull/7056"},{"url":"https://github.com/advisories/GHSA-2vcc-5v34-9jc8"}],"tags":["ghsa","npm"],"ingestedAt":"2026-06-29T14:31:47.000Z","epss":0.00405,"epssPercentile":0.31937,"slug":"CVE-2026-55661","body":"## Overview\n\nTinaCMS rich-text parsing and the default link/image renderers did not sanitize the `url` field on Slate link/image nodes. Content containing `javascript:` or `data:text/html` URLs — including case-variant, whitespace-padded, and control-character-obfuscated forms — is rendered into `href`/`src` and executes when the content is viewed. Any actor able to author rich-text content (for example a lower-privileged editor, or imported/external content) can achieve stored XSS against editors and site viewers.\n\nFixed in https://github.com/tinacms/tinacms/pull/7056 via a `sanitizeUrl()` helper (case-insensitive, whitespace/control-character-normalized scheme allow-list) applied recursively to Slate trees at parse time and in the default rich-text rendering.\n\n## Affected packages\n\n- `tinacms < 3.9.3`\n- `@tinacms/mdx < 2.1.7`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `tinacms 3.9.3`\n- `@tinacms/mdx 2.1.7`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}