Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rgr9-r7mj-mf6x | Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root |
Tue, 25 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tina
Tina tinacms |
|
| Vendors & Products |
Tina
Tina tinacms |
Wed, 19 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacms/cli/src/next/vite/cors.ts origin callback returns false for a disallowed origin but does not reject the request, and packages/@tinacms/cli/src/next/vite/plugins.ts still routes POST /media/upload/* to mediaRouter.handlePost. The upload code in packages/@tinacms/cli/src/next/commands/dev-command/server/media.ts writes attacker-controlled multipart contents inside the configured media root. A remote attacker can cause a developer's browser to submit this state-changing request by inducing the developer to visit an attacker-controlled page while tinacms dev is running. This issue is fixed in version 2.5.2. | |
| Title | Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-25T14:20:27.175Z
Reserved: 2026-07-15T16:54:55.816Z
Link: CVE-2026-63123
Updated: 2026-08-25T14:19:38.962Z
Status : Received
Published: 2026-08-19T22:16:58.710
Modified: 2026-08-25T15:16:36.760
Link: CVE-2026-63123
No data.
OpenCVE Enrichment
Updated: 2026-08-21T13:02:27Z
Github GHSA