logo

Critical 9.7 CVSS TinaCMS Flaw Exposes Local Developer Machines

ID: c58637c6-9719-5b40-9bb7-4fb22751f9a4

STIX ID: report--c58637c6-9719-5b40-9bb7-4fb22751f9a4

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-03-16

Date Updated: 2026-04-23

Author: Ddos

...
...

Security researchers disclosed CVE-2026-28792, a critical (CVSS 9.7) vulnerability in TinaCMS that combines a permissive CORS configuration with a path traversal flaw in the CLI dev server, enabling drive-by browser-based attacks against developers' local machines that can enumerate, steal, overwrite, or delete files. The report warns that attackers can abuse /media/list/ and /media/upload/ to gain comprehensive filesystem access, advises upgrading to a patched TinaCMS release (>= 2.1.8) and shutting down idle dev servers, and recommends using isolated browser profiles or VMs for development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.