PT-2025-52257 · Unknown+1 · Gray-Matter+3
Cristianstaicu
·
Published
2025-12-18
·
Updated
2025-12-22
·
CVE-2025-68278
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tina versions prior to 3.1.1
Description
Tina is a headless content management system. Versions of Tina prior to 3.1.1 improperly utilize the gray-matter package, potentially allowing attackers who control the content of markdown files—such as blog posts—to execute arbitrary code.
Recommendations
Update to Tina version 3.1.1 or later.
Update to @tinacms/cli version 2.0.4 or later.
Update to @tinacms/graphql version 2.0.3 or later.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Tinacms/Cli
@Tinacms/Graphql
Tina
Gray-Matter