@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files
- Severity:
- High
Description
A Path Traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manipulating the relativePath parameter in GraphQL mutations.
Recommendation
Update the @tinacms/graphql package to the latest compatible version. Followings are version details:
- Affected version(s): <= 2.2.1
- Patched version(s): 2.2.2
References
Related Issues
- Electerm runWidget has a path traversal that leads to arbitrary code execution - CVE-2026-43940
- @tinacms/graphql has a Path Traversal issue - CVE-2026-24125
- Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read - CVE-2026-40163
- Rollup 4 has Arbitrary File Write via Path Traversal - CVE-2026-27606
You might also like:
- Tags:
- npm
- @tinacms/graphql
Anything's wrong? Let us know Last updated on April 06, 2026


