CVE-2026-28791
Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS development server's media upload handler. The code at media.ts joins user-controlled path segments using path.join() without validating that the resulting path stays within the intended media directory. This allows writing files to arbitrary locations on the filesystem. This vulnerability is fixed in 2.1.7.
- Affected products
- Tinacms, @Tinacms/Cli
- Ssw Tinacms\/cli
- < 2.1.7
- Fix
- Available
- CVSS 3.1
- 7.4 HIGH
- EPSS
- 0.3% (25th percentile)
- Weakness
- CWE-22
- NVD status
- Analyzed
- Published
- 2026-03-12
CVE-2026-28791 at NVD
No indexed exploits for CVE-2026-28791 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-28791 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.