Project Subscriptions
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m48g-4wr2-j2h6 | TinaCMS CLI has Arbitrary File Read via Disabled Vite Filesystem Restriction |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 13 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ssw
Ssw tinacms\/cli |
|
| CPEs | cpe:2.3:a:ssw:tinacms\/cli:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Ssw
Ssw tinacms\/cli |
Fri, 13 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tina
Tina tinacms |
|
| Vendors & Products |
Tina
Tina tinacms |
Thu, 12 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite's built-in filesystem access restriction. This allows any unauthenticated attacker who can reach the dev server to read arbitrary files on the host system. This vulnerability is fixed in 2.1.8. | |
| Title | Arbitrary File Read via Disabled Vite Filesystem Restriction in TinaCMS CLI | |
| Weaknesses | CWE-200 CWE-552 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-13T16:27:22.344Z
Reserved: 2026-03-03T20:51:43.482Z
Link: CVE-2026-29066
Updated: 2026-03-13T16:27:13.369Z
Status : Analyzed
Published: 2026-03-12T17:16:50.700
Modified: 2026-03-13T19:57:18.363
Link: CVE-2026-29066
No data.
OpenCVE Enrichment
Updated: 2026-03-13T09:50:57Z
Github GHSA