Vulnerability in TinaCMS CLI Allows Unauthorized Media Uploads
CVE-2026-63123

6.5MEDIUM

Key Information:

Vendor

Tinacms

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-63123?

The TinaCMS CLI package prior to version 2.5.2 contains a vulnerability in its Vite development server. Specifically, it improperly handles CORS requests, allowing a malicious actor to exploit the origin callback, which, while returning false for disallowed origins, fails to reject the request outright. Consequently, an attacker can manipulate a developer's browser into sending state-changing requests by enticing them to visit a compromised page while the TinaCMS dev server is operational. This vulnerability permits the upload of attacker-controlled multipart contents to the configured media root, posing a significant risk if exploited.

Affected Version(s)

tinacms < 2.5.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.