
🔥 CVE-2026-34604 (tinacms/graphql FilesystemBridge): High path traversal via symlinks/junctions—escape root, arbitrary read/write. Patch: Latest tina https://www.tenable.com/cve/newest https://nvd.nist.gov/vuln/detail/CVE-2026-34604 https://github.com/tinacms/graphql/security/advisories/GHSA-...
Post summary
CVE‑2026‑34604 is a high‑severity path traversal flaw in tinacms/graphql that allows arbitrary read/write by escaping the root via symlinks or junctions; a patch is available.
