
📁 CVE-2026-34603 (tinacms/graphql Media Endpoints): High escape media root via symlinks—file disclosure/exfil. Patch: Update @tinacms/graphql https://www.tenable.com/cve/newest https://nvd.nist.gov/vuln/detail/CVE-2026-34603 https://github.com/tinacms/graphql/security/advisories
Post summary
The post announces CVE-2026-34603 affecting tinacms/graphql, details a directory escape via symlinks, and provides a patch recommendation.
