Vulnerabilities (CVE)

Filtered by vendor Ssw Subscribe
Filtered by product Tinacms
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-68278 1 Ssw 3 Tinacms, Tinacms\/cli, Tinacms\/graphql 2026-04-10 N/A 8.8 HIGH
Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in an insecure way allowing attackers that can control the content of the processed markdown files, e.g., blog posts, to execute arbitrary code. tinacms version 3.1.1, @tinacms/cli version 2.0.4, and @tinacms/graphql version 2.0.3 contain a fix for the issue.