Description
A Path Traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manipulating the relativePath parameter in GraphQL mutations.
Recommendation
Update the @tinacms/graphql package to the latest compatible version. Followings are version details:
- Affected version(s): <= 2.2.1
- Patched version(s): 2.2.2
References
Could your website be exposed too?
SmartScanner can check your website for @tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Electerm runWidget has a path traversal that leads to arbitrary code execution - CVE-2026-43940
- @tinacms/graphql has a Path Traversal issue - CVE-2026-24125
- Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read - CVE-2026-40163
- Rollup 4 has Arbitrary File Write via Path Traversal - CVE-2026-27606


