Junglewise Threat Intelligence

CVE-2026-34604: TinaCMS GraphQL FilesystemBridge path traversal via symlinks

CVE-2026-34604 · Severity: low · CVSS 3.1 · Published 2026-04-01

Technologies: @tinacms/graphql (npm). Vendors: npm, TinaCMS.

Executive brief

TinaCMS is a headless CMS used for content management and publishing. Its GraphQL API includes a file bridge component that validates paths to restrict file access to a configured content directory. However, the validation uses string-based checks that do not follow symbolic links or directory junctions, allowing attackers to read, write, or delete files outside the intended content root by exploiting symlinks that exist within the content directory.

Technical details

@tinacms/graphql's FilesystemBridge performs path containment validation using lexical string comparison (path.resolve + startsWith) rather than canonical filesystem paths. The validation blocks simple ../ traversal but fails to resolve symlink or junction targets, creating a "realpath gap": an attacker who can place or exploit a symlink/junction inside an allowed collection path (e.g., content/posts/pivot → /etc) can bypass the containment check. The vulnerable functions include get(), put(), delete(), and glob() which perform actual filesystem I/O after the flawed validation. Attack requires the symlink/junction to already exist within the content tree or for the attacker to create one before issuing GraphQL operations. The fix requires comparing canonical (realpath-resolved) paths rather than lexical string paths for all filesystem boundaries.

Affected products

  • TinaCMS @tinacms/graphql <=2.2.0

Timeline

  • 2026-03-30: disclosed
  • 2026-04-01: advisory
  • 2026-04-01: patched: Version 2.2.2 released with patch

References

Related threats