PT-2026-25012 · Npm+3 · @Tinacms/Cli+2

Alaeddine03

·

Publicado

2026-03-12

·

Atualizado

2026-03-16

·

CVE-2026-28792

CVSS v3.1

9.6

Crítica

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TinaCMS versions prior to 2.1.8
Description TinaCMS, a headless content management system, has an issue where the CLI dev server combines a permissive CORS configuration (Access-Control-Allow-Origin: *) with a path traversal vulnerability. This combination enables a browser-based drive-by attack. A remote attacker can enumerate the filesystem, write arbitrary files, and delete arbitrary files on developer machines by tricking them into visiting a malicious website while the TinaCMS dev server is running. The attack flow involves the developer running tinacms dev, then unknowingly visiting an attacker-controlled page. The attacker's JavaScript exploits the CORS misconfiguration and path traversal to read sensitive files, which are then exfiltrated to the attacker's server. The vulnerable component is the TinaCMS dev server, specifically the CORS configuration and the path traversal functionality. The API endpoint /media/upload/ is susceptible to path traversal, allowing attackers to write arbitrary files. The API endpoint /media/ allows for file deletion via the DELETE method, also vulnerable to path traversal. The /media/list/ endpoint allows for filesystem enumeration.
Recommendations Update to TinaCMS version 2.1.8 or later.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-28792
GHSA-8PW3-9M7F-Q734

Produtos afetados

@Tinacms/Cli
Cli
Tinacms