TinaCMS是Tina开源的一个用于 Markdown、MDX 和 JSON 的开源无头 CMS。 TinaCMS 2.1.2之前版本存在路径遍历漏洞,该漏洞源于使用path.join()组合路径时未验证解析后的路径是否保持在集合根目录内,可能导致目录遍历攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-28792 | 9.7 CRITICAL | Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS |
| CVE-2026-28793 | 8.4 HIGH | Path Traversal Leading to Arbitrary File Read, Write and Delete in TinaCMS |
| CVE-2026-29066 | 6.2 MEDIUM | Arbitrary File Read via Disabled Vite Filesystem Restriction in TinaCMS CLI |
No comments yet