Sploitus

CVE-2026-63123

No indexed exploits for CVE-2026-63123 yet

Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacms/cli/src/next/vite/cors.ts origin callback returns false for a disallowed origin but does not reject the request, and packages/@tinacms/cli/src/next/vite/plugins.ts still routes POST /media/upload/* to mediaRouter.handlePost. The upload code in packages/@tinacms/cli/src/next/commands/dev-command/server/media.ts writes attacker-controlled multipart contents inside the configured media root. A remote attacker can cause a developer's browser to submit this state-changing request by inducing the developer to visit an attacker-controlled page while tinacms dev is running. This issue is fixed in version 2.5.2.

Affected products
Tinacms
CVSS 3.1
6.5 MEDIUM
EPSS
0.2% (9th percentile)
Weakness
CWE-352
NVD status
Received
Published
2026-08-19
CVE-2026-63123 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-63123 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-63123 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.