Home

Description

Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manipulating the relativePath parameter in GraphQL mutations. The impact includes the ability to replace critical server configuration files and potentially execute arbitrary commands by sabotaging build script. This issue has been patched in version 2.2.2.

PUBLISHED Reserved 2026-03-24 | Published 2026-04-01 | Updated 2026-04-03 | Assigner GitHub_M




HIGH: 8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Problem types

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-73: External Control of File Name or Path

Product status

< 2.2.2
affected

References

github.com/...inacms/security/advisories/GHSA-v9p7-gf3q-h779

cve.org (CVE-2026-33949)

nvd.nist.gov (CVE-2026-33949)

Download JSON