In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Improper Verification of Source of a Communication Channel vulnerabilities in an interactive lesson.
Start learningUpgrade tinacms to version 3.9.3 or higher.
tinacms is a headless content management system with support for Markdown, MDX, JSON, YAML, and more.
Affected versions of this package are vulnerable to Improper Verification of Source of a Communication Channel via improper validation of cross-origin messages in the window message listeners. An attacker can hijack authenticated editing sessions by sending crafted postMessage events from a malicious origin.