In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Improper Verification of Source of a Communication Channel vulnerabilities in an interactive lesson.
Start learningUpgrade @tinacms/app to version 2.5.6 or higher.
Affected versions of this package are vulnerable to Improper Verification of Source of a Communication Channel via improper validation of cross-origin messages in the window message listeners. An attacker can hijack authenticated editing sessions by sending crafted postMessage events from a malicious origin.