GHSA-g87c-r2jp-293w
HIGHCVE-2026-34603@tinacms/cli recently added lexical path-traversal checks to the dev media routes, but the implementation still validates only the path string and does not resolve symlink or junction targets.
- Affected
- <= 2.2.1
- Fixed in
- 2.2.2
- Weakness
- CWE-22
- Published
- 2026-04-01
- Source
- github