CVE-2026-28792Disclosure(ssw / tinacms\/cli)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ssw tinacms\/cli systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Allow-Origin: *) with the path traversal vulnerability (previously reported) to enable a browser-based drive-by attack. A remote attacker can enumerate the filesystem, write arbitrary files, and delete arbitrary files on developer's machines by simply tricking them into visiting a malicious website while tinacms dev is running. This vulnerability is fixed in 2.1.8.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-942

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tinacms\/cli

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-12); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
tinacms\/cli

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-12: 4Mentions · 2026-03-16: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-12: 4Technical Details · 2026-03-16: 103-1203-16
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-124
Disclosure3Patch1
2026-03-161
Patch1
Full discourse5 posts
  • Gray Hats@the_yellow_fall
    Patch

    Critical 9.7 CVSS flaw in TinaCMS (CVE-2026-28792) lets attackers hijack local developer machines via CORS and path traversal. Patch to 2.1.8 immediately. #TinaCMS #CVE #CyberSecurity #InfoSec #PathTraversal #CORS #DeveloperSecurity #Vulnerability https://securityonline.info/drive-by-hijack-critical-9-7-cvss-tinacms-flaw-cve-2026-28792/ https://t.co/Ggm5FiZzNH

    Post summary

    The tweet announces a critical CVSS 9.7 vulnerability in TinaCMS (CVE-2026-28792) that enables local developer machine hijacking via CORS and path traversal, and urges immediate patching to version 2.1.8.

    03071442
    10.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28792 Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Allow-Origin: *) wi… https://www.cve.org/CVERecord?id=CVE-2026-28792

    Post summary

    The text announces a CORS misconfiguration in TinaCMS’s CLI dev server before version 2.1.8, providing technical details but no PoC, exploit, or patch information.

    00000151
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-28792: CRITICAL] Headless CMS Tina had a security flaw allowing remote attackers to manipulate files on developer's machines. Update to TinaCMS 2.1.8 to fix this critical issue.#cve,CVE-2026-28792,#cybersecurity https://cvefind.com/CVE-2026-28792

    Post summary

    A critical file manipulation vulnerability was disclosed for TinaCMS, and the vendor recommends updating to version 2.1.8 to mitigate the issue.

    0000039
    601 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28792 - Critical Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Allow-Origin: *) with the path traversal... https://www.thehackerwire.com/vulnerability/CVE-2026-28792/ https://t.co/KEF15LdbyF

    Post summary

    The tweet announces CVE‑2026‑28792 as a critical flaw in TinaCMS CLI, highlighting a permissive CORS setting that enables path traversal, but provides no PoC, exploit code, or patch information.

    0000037
    134 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-28792: Cross-Origin File Exfiltration v... Drive-by filesystem takeover through wildcard CORS + path traversal - one malicious webpage can own your entire dev mac... https://zerodaysignal.com/vulnerability/CVE-2026-28792 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑28792, detailing a drive‑by filesystem takeover via wildcard CORS and path traversal, without evidence of existing PoC, exploitation, or patch information.

    0000039
    143 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsswtinacms\/cli-node.js-

Explore more