[Tina](https://tina.io) is a headless content management system with support for Markdown, MDX, JSON, YAML, and more. This package contains the logic required to turn a collection of folders and files into a database that can be queried using [GraphQL](ht
93%
Total Score
64
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-34604 @tinacms/graphql is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 2.2.0. | 0.0.0 - 2.2.0 | High |
CVE-2026-34603 @tinacms/graphql is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 2.2.1. | 0.0.0 - 2.2.1 | High |
CVE-2026-33949 @tinacms/graphql is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 2.2.1. | 0.0.0 - 2.2.1 | High |
CVE-2026-24125 @tinacms/graphql is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 2.1.1. | 0.0.0 - 2.1.1 | Medium |
AIKIDO-2026-10283 @tinacms/graphql is vulnerable to Path Traversal in versions 1.0.0 - 2.1.2. | 1.0.0 - 2.1.2 | High |
| Dependency | Last Release | Score |
|---|---|---|
yup Version ^1.6.1 | — | — |
graphql Version 15.8.0 | — | — |
js-sha1 Version ^0.6.0 | — | — |
js-yaml Version ^3.14.1 | — | — |
date-fns Version ^2.30.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant