TinaCMS是Tina开源的一个用于 Markdown、MDX 和 JSON 的开源无头 CMS。 TinaCMS 2.1.8之前版本存在路径遍历漏洞,该漏洞源于TinaCMS CLI开发服务器暴露的媒体端点存在路径遍历问题,可能导致攻击者读取和写入文件系统上预期媒体目录之外的任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-28792 | 9.7 CRITICAL | Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS |
| CVE-2026-24125 | 6.3 MEDIUM | Path Traversal in @tinacms/graphql |
| CVE-2026-29066 | 6.2 MEDIUM | Arbitrary File Read via Disabled Vite Filesystem Restriction in TinaCMS CLI |
No comments yet