-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the Codegen class writing the complete schema configuration to tina-lock.json. The commit diff shows the addition of logic to explicitly remove the 'search' property from the schema config before writing it. In vulnerable versions (<1.6.2), this filtering was absent, causing the search token to be included in the generated lock file. The file path and class/method are explicitly referenced in the commit diff, and the CWE mappings (CWE-200/CWE-312) confirm this is a cleartext storage/exposure issue.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| @tinacms/cli | npm | < 1.6.2 | 1.6.2 |
Ongoing coverage of React2Shell