Description
Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite's built-in filesystem access restriction. This allows any unauthenticated attacker who can reach the dev server to read arbitrary files on the host system. This vulnerability is fixed in 2.1.8.
Problem types
CWE-552: Files or Directories Accessible to External Parties
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Product status
References
github.com/...inacms/security/advisories/GHSA-m48g-4wr2-j2h6
github.com/...inacms/security/advisories/GHSA-m48g-4wr2-j2h6