CVE-2026-34604
- EPSS 0.37%
- Veröffentlicht 01.04.2026 16:05:15
- Zuletzt bearbeitet 07.04.2026 19:08:26
Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containment checks in FilesystemBridge. That blocks plain ../ traversal, but it does not resolve symlink or junction targets. If a symlink/j...
CVE-2026-33949
- EPSS 0.39%
- Veröffentlicht 01.04.2026 15:54:12
- Zuletzt bearbeitet 07.04.2026 19:17:35
Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manipulating the...
CVE-2026-24125
- EPSS 0.43%
- Veröffentlicht 12.03.2026 16:31:56
- Zuletzt bearbeitet 13.03.2026 19:22:04
Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content documents using relative file paths (relativePath, newRelativePath) via GraphQL mutations. Under certain conditions, these paths ...