Ssw

Tinacms/graphql

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.08%
  • Veröffentlicht 01.04.2026 16:05:15
  • Zuletzt bearbeitet 07.04.2026 19:08:26

Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containment checks in FilesystemBridge. That blocks plain ../ traversal, but it does not resolve symlink or junction targets. If a symlink/j...

  • EPSS 0.15%
  • Veröffentlicht 01.04.2026 15:54:12
  • Zuletzt bearbeitet 07.04.2026 19:17:35

Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manipulating the...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 12.03.2026 16:31:56
  • Zuletzt bearbeitet 13.03.2026 19:22:04

Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content documents using relative file paths (relativePath, newRelativePath) via GraphQL mutations. Under certain conditions, these paths ...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 18.12.2025 15:27:21
  • Zuletzt bearbeitet 10.04.2026 17:34:56

Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in an insecure way allowing attackers that can control the content of the processed markdown files, e.g., blog posts, to execute arb...