Vulnerability library
Security checkMarch 12, 2026

@tinacms/graphql has a Path Traversal issue

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpm@tinacms/graphql

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

TinaCMS allows users to create, update, and delete content documents using relative file paths (relativePath, newRelativePath) via GraphQL mutations. Under certain conditions, these paths are combined with the collection path using path.join() without validating that the resolved path remains within the collection root directory.

Recommendation

Update the @tinacms/graphql package to the latest compatible version. Followings are version details:

  • Affected version(s): <= 2.1.1
  • Patched version(s): 2.1.2

References

Could your website be exposed too?

SmartScanner can check your website for @tinacms/graphql has a Path Traversal issue and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated March 12, 2026