Vulnerabilities/

@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files

Severity:
High

Description

A Path Traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manipulating the relativePath parameter in GraphQL mutations.

Recommendation

Update the @tinacms/graphql package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@tinacms/graphql
Anything's wrong? Let us know Last updated on April 06, 2026