/Vulnerability Library

TinaCMS - Path Traversal

CVE-2026-29066
Verified

Description

TinaCMS CLI < 2.1.8 contains a file system read vulnerability caused by disabled Vite server.fs.strict setting, letting unauthenticated attackers read arbitrary files on the host system, exploit requires access to the dev server.

Severity

Medium

CVSS Score

6.2

Exploit Probability

1%

Affected Product

tinacms

Published Date

April 7, 2026

Template Author

theamanrawat

CVE-2026-29066.yaml
6.2Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-29066
CWE ID:
cwe-200

References

https://github.com/tinacms/tinacms/security/advisories/GHSA-m48g-4wr2-j2h6https://nvd.nist.gov/vuln/detail/CVE-2026-29066

Remediation Steps

Update to version 2.1.8 or later.