CVE-2026-28792: Ssw Tinacms/cli
Critical severity, CVSS 9.6. EPSS: 0.7% chance of exploitation in the next 30 days.
Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Allow-Origin: *) with the path traversal vulnerability (previously reported) to enable a browser-based drive-by attack. A remote attacker can enumerate the filesystem, write arbitrary files, and delete arbitrary files on developer's machines by simply tricking them into visiting a malicious website while tinacms dev is running. This vulnerability is fixed in 2.1.8.
Affected products
- Ssw Tinacms/cli: before 2.1.8 (fixed in 2.1.8)
Published 2026-03-12. Last modified 2026-06-17.