LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-28791

ssw · tinacms\/cli

Published
CVSS7.4
Severityhigh
WeaknessCWE-22
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

Description

Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS development server's media upload handler. The code at media.ts joins user-controlled path segments using path.join() without validating that the resulting path stays within the intended media directory. This allows writing files to arbitrary locations on the filesystem. This vulnerability is fixed in 2.1.7.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-28791

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-28791.