PoC Index

CVE-2026-29066

MEDIUM 6.2EPSS 1.0%

Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite's built-in filesystem access restriction. This allows any unauthenticated attacker who can reach the dev server to read arbitrary files on the host system. This vulnerability is fixed in 2.1.8.

CVSS v3.1
6.2 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v3.1
6.2 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.03% chance of exploitation in the next 30 days, 61th percentile
Nuclei
medium · CWE-200
Published
2026-03-12
Updated
2026-03-13

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related