Sensitive Information leaked via script File in TinaCMS. Sites building with @tinacms/cli >= 1.0.0 && < 1.0.9 that store sensitive values in process.env var are impacted. If you're on a version prior to 1.0.0 this vulnerability does not affect you.
If your Tina-enabled website has sensitive credentials stored as environment variables (eg. Algolia API keys) you should rotate those keys immediately.
This issue has been patched in @tinacms/cli@1.0.9
Upgrading, and rotating secure & exposed keys is required for the proper fix.
https://github.com/tinacms/tinacms/pull/3584
{ "github_reviewed": true, "cwe_ids": [ "CWE-200" ], "nvd_published_at": "2023-02-08T20:15:00Z", "github_reviewed_at": "2023-02-08T18:18:05Z", "severity": "HIGH" }