MEDIUM
tinacms
CVE published 2026-08-19
CVE-2026-59992
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:16:40.600Z and has not been modified since then. The first-party production media adapters in Tina CMS passed attacker-controlled object keys to storage SDK upload and delete operations without enforcing the operator's configured mediaRoot. This allowed authenticated CMS editors to create or d [truncated]