cbcvebase.
CVE-2026-34603
published 2026-04-01

CVE-2026-34603: Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal checks to the dev media routes, but…

PriorityP354high8.3CVSS 3.1
AVNACLPRLUINSUCHIHAL
EPSS
0.41%
32.6th percentile
Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal checks to the dev media routes, but the implementation still validates only the path string and does not resolve symlink or junction targets. If a link already exists under the media root, Tina accepts a path like pivot/written-from-media.txt as "inside" the media directory and then performs real filesystem operations through that link target. This allows out-of-root media listing and write access, and the same root cause also affects delete. This issue has been patched in version 2.2.2.

Affected

3 ranges
VendorProductVersion rangeFixed in
sswtinacms_cli<= 2.2.1
tinacmsgraphql>= 0 < 2.2.22.2.2
tinacmstinacms< 2.2.22.2.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.