Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/@tinacms/graphql — 5 CVEs · VulnScope
pkg:npm/
@tinacms/graphql
5 total CVEs
HIGH
3
MEDIUM
1
✅ Check your installed version
Check
All known vulnerabilities
HIGH
8.1
CVE-2026-33949
@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files
from 0, < 2.2.2
HIGH
7.1
CVE-2026-34604
@tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions
from 0, < 2.2.2
HIGH
7.1
CVE-2026-34603
@tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions
from 0, < 2.2.2
MEDIUM
6.3
@tinacms/graphql has a Path Traversal issue
from 0, < 2.1.2
—
tinacms is vulnerable to arbitrary code execution
from 0, < 2.0.3
CVE-2026-24125
CVE-2025-68278