Critical 9.7 CVSS TinaCMS Flaw Exposes Local Developer Machines
ID: c58637c6-9719-5b40-9bb7-4fb22751f9a4
STIX ID: report--c58637c6-9719-5b40-9bb7-4fb22751f9a4
Feed Name: securityonline.info
Security researchers disclosed CVE-2026-28792, a critical (CVSS 9.7) vulnerability in TinaCMS that combines a permissive CORS configuration with a path traversal flaw in the CLI dev server, enabling drive-by browser-based attacks against developers' local machines that can enumerate, steal, overwrite, or delete files. The report warns that attackers can abuse /media/list/ and /media/upload/ to gain comprehensive filesystem access, advises upgrading to a patched TinaCMS release (>= 2.1.8) and shutting down idle dev servers, and recommends using isolated browser profiles or VMs for development.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
