Junglewise Threat Intelligence

CVE-2026-34603: Tina CMS GraphQL media endpoints path traversal via symlinks

CVE-2026-34603 · Severity: low · CVSS 3.1 · Published 2026-04-01

Technologies: @tinacms/graphql (npm). Vendors: npm.

Executive brief

Tina CMS's media management endpoints can be manipulated to read, write, and delete files outside the intended media directory by exploiting symlinks or junctions. An authenticated attacker can list files, upload files to, or remove files from locations outside the media root—potentially exposing sensitive data or compromising system integrity. This is especially dangerous in development and self-hosted deployments where symlinks in the media directory are common.

Technical details

The vulnerability is a path traversal flaw in @tinacms/graphql's media endpoints (list, upload, delete). The vulnerable code validates user-controlled file paths using lexical string operations (path.resolve and startsWith checks) without resolving symbolic links or Windows junctions. An attacker can craft a path like `pivot/secret.txt` where `pivot` is a symlink to a directory outside the media root; the validation passes because the path string appears to be inside the media directory, but filesystem operations follow the symlink target and access files outside the boundary. Attack requires authenticated access (PR:L) with moderate complexity (AC:H), allowing unauthorized file read/write/delete operations with high confidentiality and integrity impact. The patch (version 2.2.2) hardens validation by using fs.realpath() to resolve canonical paths and comparing real filesystem locations rather than strings.

Affected products

  • Tina CMS GraphQL <= 2.2.1

Timeline

  • 2026-04-01: disclosed
  • 2026-04-01: patched: Version 2.2.2

References

Related threats