CVE-2026-33949
Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manipulating the relativePath parameter in GraphQL mutations. The impact includes the ability to replace critical server configuration files and potentially execute arbitrary commands by sabotaging build script. This issue has been patched in version 2.2.2.
- Affected products
- @Tinacms/Graphql, Tinacms
- Ssw Tinacms\/graphql
- ≤ 2.2.1
- Fix
- Available
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 0.4% (31th percentile)
- Weakness
- CWE-22, CWE-73
- NVD status
- Analyzed
- Published
- 2026-04-01
CVE-2026-33949 at NVD
No indexed exploits for CVE-2026-33949 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-33949 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.