Junglewise Threat Intelligence

CVE-2026-24125: TinaCMS graphql path traversal in document mutations

CVE-2026-24125 · Severity: low · CVSS 3.1 · Published 2026-03-12

Technologies: @tinacms/graphql (npm), TinaCMS GraphQL. Vendors: TinaCMS, npm.

Executive brief

TinaCMS is an open-source headless CMS that stores content files in a Git repository. A path traversal vulnerability in its GraphQL API allows authenticated editors to create, move, or delete files outside their assigned content directories by using directory traversal sequences. While the impact is limited by schema validation and git tracking, a malicious insider with editor permissions could delete critical configuration files or move sensitive documents outside the collection root.

Technical details

The vulnerability exists in @tinacms/graphql's document mutation handlers (createDocument, updateDocument, deleteDocument, createFolder), which use path.join() to combine collection paths with user-supplied relativePath parameters without validating that the resulting path remains within the collection root directory. An attacker with authenticated GraphQL mutation permissions can inject ../ sequences to escape the collection boundary. The attack vector is network-based and requires low-privilege editor authentication. Mitigating factors include: (1) created/updated content must conform to the collection's GraphQL schema, preventing arbitrary file content injection; (2) all file operations are tracked in git, making changes visible and reversible; and (3) anonymous users cannot access these mutations. The vulnerability does not allow silent modifications or unauthenticated exploitation. Patched in version 2.1.2; affected versions are <= 2.1.1.

Affected products

  • TinaCMS @tinacms/graphql <= 2.1.1

Timeline

  • 2026-03-12: disclosed: Vulnerability published on GitHub Security Advisory
  • 2026-03-12: patched: Fix released in version 2.1.2

References

Related threats