CVE-2026-63123 | TinaCMS up to 2.5.1 CORS cors.ts cross-domain policy

SecurityVulns

A vulnerability has been found in TinaCMS up to 2.5.1 and classified as problematic. Affected is an unknown function of the file packages/@tinacms/cli/src/next/vite/cors.ts of the component CORS. The manipulation leads to permissive cross-domain policy with untrusted domains.

This vulnerability is uniquely identified as CVE-2026-63123. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded.VulDB Recent EntriesRead More