Skip to content

TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes

Moderate severity GitHub Reviewed Published Jun 17, 2026 in tinacms/tinacms

No open alerts for this advisory

Give feedback on Dependabot alerts