Sploitus

CVE-2026-28793

No indexed exploits for CVE-2026-28793 yet

Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path traversal, allowing attackers to read and write arbitrary files on the filesystem outside the intended media directory. When running tinacms dev, the CLI starts a local HTTP server (default port 4001) exposing endpoints such as /media/list/*, /media/upload/*, and /media/*. These endpoints process user-controlled path segments using decodeURI() and path.join() without validating that the resolved path remains within the configured media directory. This vulnerability is fixed in 2.1.8.

Affected products
@Tinacms/Cli, Cli, Tinacms
Ssw Tinacms\/cli
< 2.1.8
Fix
Available
CVSS 3.1
8.4 HIGH
EPSS
0.2% (10th percentile)
Weakness
CWE-22
NVD status
Analyzed
Published
2026-03-12
CVE-2026-28793 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-28793 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-28793 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.