CVE-2026-28793Disclosure(ssw / tinacms\/cli)

LOWCVSS 8.4 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path traversal, allowing attackers to read and write arbitrary files on the filesystem outside the intended media directory. When running tinacms dev, the CLI starts a local HTTP server (default port 4001) exposing endpoints such as /media/list/*, /media/upload/*, and /media/*. These endpoints process user-controlled path segments using decodeURI() and path.join() without validating that the resolved path remains within the configured media directory. This vulnerability is fixed in 2.1.8.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tinacms\/cli

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
tinacms\/cli

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-12: 3Technical Details · 2026-03-12: 303-12
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-28793 Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path traversal, allowi… https://www.cve.org/CVERecord?id=CVE-2026-28793

    Post summary

    CVE-2026-28793 impacts TinaCMS CLI versions before 2.1.8, exposing a path traversal flaw in its media endpoints.

    00010148
    56.7K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 TinaCMS CLI, Path Traversal, #CVE-2026-28793 (High) https://dailycve.com/tinacms-cli-path-traversal-cve-2026-28793-high/

    Post summary

    A high‑severity path traversal vulnerability (CVE‑2026‑28793) has been disclosed for TinaCMS CLI.

    0000035
    167 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28793 - High Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path traversal, allowing attackers to read and ... https://www.thehackerwire.com/vulnerability/CVE-2026-28793/ https://t.co/4Q1sQGLY45

    Post summary

    The tweet announces a high‑severity path‑traversal flaw in TinaCMS CLI (v<2.1.8) with limited technical detail; no PoC, exploit, or patch information is provided.

    0000032
    134 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsswtinacms\/cli-node.js-

Explore more