CVE-2026-33949
HIGH@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files
Title source: cnaDescription
Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manipulating the relativePath parameter in GraphQL mutations. The impact includes the ability to replace critical server configuration files and potentially execute arbitrary commands by sabotaging build script. This issue has been patched in version 2.2.2.
Scores
CVSS v3
8.1
EPSS
0.0012
EPSS Percentile
30.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
CWE-73
Status
published
Products (3)
ssw/tinacms\/graphql
< 2.2.1
tinacms/graphql
0 - 2.2.2npm
tinacms/tinacms
< 2.2.2
Published
Apr 01, 2026
Tracked Since
Apr 01, 2026