@tinacms/cli is vulnerable to Path Traversal
70
High Risk
Affected versions of this package are vulnerable to a path traversal vulnerability that allowed directory escape via CLI media and filesystem operations due to insufficient validation of resolved paths against a trusted base directory. An attacker could exploit this by supplying crafted file paths (including percent-encoded traversal payloads such as ..%2f..%2f) to media upload, delete, list, or filesystem get/put/glob routes, potentially reading, overwriting, or deleting arbitrary files outside the intended project scope, leading to unauthorized data exposure or integrity compromise.
You are affected if you are using a version that falls within the vulnerable range.
@tinacms/cli is vulnerable to Path Traversal in versions 1.0.0 - 2.1.6.
Upgrade the @tinacms/cli library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant