Files or Directories Accessible to External Parties Affecting @tinacms/cli package, versions <2.1.8


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.02% (7th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-TINACMSCLI-15518077
  • published13 Mar 2026
  • disclosed12 Mar 2026
  • creditalaeddine03

Introduced: 12 Mar 2026

NewCVE-2026-29066  (opens in a new tab)
CWE-552  (opens in a new tab)

How to fix?

Upgrade @tinacms/cli to version 2.1.8 or higher.

Overview

@tinacms/cli is a package used to set up your project with Tina Cloud configuration, and run a local version of the Tina Cloud content-api.

Affected versions of this package are vulnerable to Files or Directories Accessible to External Parties via the dev server configuration when server.fs.strict is set to false. An attacker can access sensitive files on the host system by sending crafted requests to the development server.

PoC

curl http://localhost:4001/etc/passwd

References

CVSS Base Scores

version 4.0
version 3.1