TinaCMS CLI < 2.1.8 contains a file system read vulnerability caused by disabled Vite server.fs.strict setting, letting unauthenticated attackers read arbitrary files on the host system, exploit requires access to the dev server.
id: CVE-2026-29066
info:
name: TinaCMS - Path Traversal
author: theamanrawat
severity: medium
...