CVE-2026-33949

Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manipulating the relativePath parameter in GraphQL mutations. The impact includes the ability to replace critical server configuration files and potentially execute arbitrary commands by sabotaging build script. This issue has been patched in version 2.2.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ssw:tinacms\/graphql:*:*:*:*:*:node.js:*:*

History

07 Apr 2026, 19:17

Type Values Removed Values Added
CPE cpe:2.3:a:ssw:tinacms\/graphql:*:*:*:*:*:node.js:*:*
References () https://github.com/tinacms/tinacms/security/advisories/GHSA-v9p7-gf3q-h779 - () https://github.com/tinacms/tinacms/security/advisories/GHSA-v9p7-gf3q-h779 - Vendor Advisory
First Time Ssw tinacms\/graphql
Ssw

01 Apr 2026, 17:28

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-01 17:28

Updated : 2026-04-07 19:17


NVD link : CVE-2026-33949

Mitre link : CVE-2026-33949

CVE.ORG link : CVE-2026-33949


JSON object : View

Products Affected

ssw

  • tinacms\/graphql
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-73

External Control of File Name or Path