Description
| Field | Value | |——-|——-| | Package | @tinacms/cli | | Version | 2.0.5 (latest at time of discovery) | | Vulnerable File | packages/@tinacms/cli/src/next/commands/dev-command/server/media.ts | | Vulnerable Lines | 42-43 |
Recommendation
Update the tinacms package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.1.7
- Patched version(s): 2.1.7
References
Related Issues
- @tinacms/graphql has a Path Traversal issue - CVE-2026-24125
- @tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files - CVE-2026-33949
- Agnai vulnerable to Relative Path Traversal in Image Upload - CVE-2024-47171
- @tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions - CVE-2026-34603
You might also like:
- Tags:
- npm
- tinacms
Anything's wrong? Let us know Last updated on March 12, 2026


