CVE-2026-33949 is a path traversal vulnerability found in the @tinacms/graphql component of Tina CMS, a headless content management system, affecting versions prior to 2.2.2. This flaw allows unauthenticated users to write and overwrite arbitrary files within the project root by manipulating the relativePath parameter in GraphQL mutations. Rated with a CVSS score of 8.1 (High), the vulnerability poses a significant risk, enabling potential replacement of critical server configuration files and arbitrary command execution. While there is no public exploit code available and it is not currently listed in CISA's KEV catalog, the vulnerability is on a "Hot List" and has generated some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2.1CPE matchmatch criteria | cpe:2.3:a:ssw:tinacms\/graphql:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.