CVE-2026-28791
Path Traversal in Media Upload Handle in Tina
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7.4EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
12 mar 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS development server's media upload handler. The code at media.ts joins user-controlled path segments using path.join() without validating that the resulting path stays within the intended media directory. This allows writing files to arbitrary locations on the filesystem. This vulnerability is fixed in 2.1.7.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Productos afectados
tinacms · tinacms¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →