CVE-2026-33949

HIGH

@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files

Title source: cna
STIX 2.1

Description

Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manipulating the relativePath parameter in GraphQL mutations. The impact includes the ability to replace critical server configuration files and potentially execute arbitrary commands by sabotaging build script. This issue has been patched in version 2.2.2.

Scores

CVSS v3 8.1
EPSS 0.0012
EPSS Percentile 30.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22 CWE-73
Status published
Products (3)
ssw/tinacms\/graphql < 2.2.1
tinacms/graphql 0 - 2.2.2npm
tinacms/tinacms < 2.2.2
Published Apr 01, 2026
Tracked Since Apr 01, 2026