TinaCMS - Path Traversal
CVE-2026-29066
Verified
Description
TinaCMS CLI < 2.1.8 contains a file system read vulnerability caused by disabled Vite server.fs.strict setting, letting unauthenticated attackers read arbitrary files on the host system, exploit requires access to the dev server.
Severity
Medium
CVSS Score
6.2
Exploit Probability
1%
Affected Product
tinacms
Published Date
April 7, 2026
Template Author
theamanrawat
CVE-2026-29066.yaml
6.2Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-29066
CWE ID:
cwe-200
Remediation Steps
Update to version 2.1.8 or later.