Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rgr9-r7mj-mf6x | Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root |
Wed, 19 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacms/cli/src/next/vite/cors.ts origin callback returns false for a disallowed origin but does not reject the request, and packages/@tinacms/cli/src/next/vite/plugins.ts still routes POST /media/upload/* to mediaRouter.handlePost. The upload code in packages/@tinacms/cli/src/next/commands/dev-command/server/media.ts writes attacker-controlled multipart contents inside the configured media root. A remote attacker can cause a developer's browser to submit this state-changing request by inducing the developer to visit an attacker-controlled page while tinacms dev is running. This issue is fixed in version 2.5.2. | |
| Title | Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-19T21:41:18.687Z
Reserved: 2026-07-15T16:54:55.816Z
Link: CVE-2026-63123
No data.
Status : Received
Published: 2026-08-19T22:16:58.710
Modified: 2026-08-19T22:16:58.710
Link: CVE-2026-63123
No data.
OpenCVE Enrichment
No data.
Github GHSA