THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-g74q-6g2f-874x (high) — Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site

[GHSA] GHSA-g74q-6g2f-874x (high) — Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site

highgithub_advisoriesPublished 2026-09-17

GHSA-g74q-6g2f-874x Severity: high CVE: CVE-2026-63506

Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site

## Summary

`@tinacms/auth`'s `isAuthorized(req)` decides authorization by validating the caller's bearer token against `https://identity.tinajs.io/v2/apps/${req.query.clientID}/currentUser`, where the `clientID` comes from the request and is nev

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-g74q-6g2f-874x