CVE-2026-28791 identifies a path traversal vulnerability (CWE-22) in the TinaCMS development server's media upload handler, affecting ssw tinacms/cli versions prior to 2.1.7. This flaw allows an unauthenticated attacker to write arbitrary files to any location on the filesystem. Rated 7.4 HIGH (CVSS:3.1), this vulnerability has a network attack vector and high attack complexity, allowing an attacker to achieve high integrity and availability impacts without user interaction. There is currently no evidence of active exploitation, nor are public exploit modules available in common frameworks, indicating low current exploitability and limited community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1.7CPE matchmatch criteria | cpe:2.3:a:ssw:tinacms\/cli:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.