Vulnerability in TinaCMS CLI Allows Unauthorized Media Uploads
CVE-2026-63123
6.5MEDIUM
What is CVE-2026-63123?
The TinaCMS CLI package prior to version 2.5.2 contains a vulnerability in its Vite development server. Specifically, it improperly handles CORS requests, allowing a malicious actor to exploit the origin callback, which, while returning false for disallowed origins, fails to reject the request outright. Consequently, an attacker can manipulate a developer's browser into sending state-changing requests by enticing them to visit a compromised page while the TinaCMS dev server is operational. This vulnerability permits the upload of attacker-controlled multipart contents to the configured media root, posing a significant risk if exploited.
Affected Version(s)
tinacms < 2.5.2
