TinaCMS是Tina开源的一个用于 Markdown、MDX 和 JSON 的开源无头 CMS。 TinaCMS 2.1.8之前版本存在安全漏洞,该漏洞源于TinaCMS CLI开发服务器配置了宽松的CORS策略,结合路径遍历漏洞,可能导致远程攻击者通过恶意网站枚举、写入和删除开发者机器上的任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-28793 | 8.4 HIGH | Path Traversal Leading to Arbitrary File Read, Write and Delete in TinaCMS |
| CVE-2026-24125 | 6.3 MEDIUM | Path Traversal in @tinacms/graphql |
| CVE-2026-29066 | 6.2 MEDIUM | Arbitrary File Read via Disabled Vite Filesystem Restriction in TinaCMS CLI |
No comments yet