CVE-2026-108260 | tinacms Tina up to 0.2.0 tina-markdown tina-markdown.js cross-domain policy
A vulnerability described as problematic has been identified in tinacms Tina up to 0.2.0. This affects an unknown part of the file tinacms/web-components/src/tina-markdown.js of the component tina-markdown. The manipulation results in permissive cross-domain policy with untrusted domains.
This vulnerability is reported as CVE-2026-108260. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More