Sensitive Information leaked via script File in TinaCMS. Sites building with @tinacms/cli >= 1.0.0 && < 1.0.9 that store sensitive values in process.env var are impacted. If you're on a version prior to 1.0.0 this vulnerability does not affect you.
If your Tina-enabled website has sensitive credentials stored as environment variables (eg. Algolia API keys) you should rotate those keys immediately.
This issue has been patched in @tinacms/cli@1.0.9
Upgrading, and rotating secure & exposed keys is required for the proper fix.
{
"cwe_ids": [
"CWE-200"
],
"github_reviewed": true,
"github_reviewed_at": "2023-02-08T18:18:05Z",
"nvd_published_at": "2023-02-08T20:15:00Z",
"severity": "HIGH"
}