Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-g9c2-gf25-3x67 | @tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions |
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ssw
Ssw tinacms\/graphql |
|
| CPEs | cpe:2.3:a:ssw:tinacms\/graphql:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Ssw
Ssw tinacms\/graphql |
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tina
Tina tinacms |
|
| Vendors & Products |
Tina
Tina tinacms |
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containment checks in FilesystemBridge. That blocks plain ../ traversal, but it does not resolve symlink or junction targets. If a symlink/junction already exists under the allowed content root, a path like content/posts/pivot/owned.md is still considered "inside" the base even though the real filesystem target can be outside it. As a result, FilesystemBridge.get(), put(), delete(), and glob() can operate on files outside the intended root. This issue has been patched in version 2.2.2. | |
| Title | @tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions | |
| Weaknesses | CWE-22 CWE-59 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-01T17:59:46.120Z
Reserved: 2026-03-30T17:15:52.500Z
Link: CVE-2026-34604
Updated: 2026-04-01T17:59:37.575Z
Status : Analyzed
Published: 2026-04-01T17:28:41.280
Modified: 2026-04-07T19:08:26.790
Link: CVE-2026-34604
No data.
OpenCVE Enrichment
Updated: 2026-04-08T19:57:05Z
Github GHSA