PatchSiren

tinacms CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM tinacms CVE published 2026-08-19

CVE-2026-63123

The CVE-2026-63123 vulnerability affects TinaCMS CLI, specifically the Vite dev server, allowing a remote attacker to submit a state-changing request by inducing a developer to visit an attacker-controlled page. This issue, fixed in version 2.5.2, has a MEDIUM severity with a CVSS score of 6.5. Developers should update to the latest version and restrict access to the media root. The vulnerability involves [truncated]

MEDIUM tinacms CVE published 2026-08-19

CVE-2026-59992

An authenticated CMS editor can create or delete objects anywhere the deployment's storage credential can reach due to missing key-boundary checks in the first-party production media adapters of Tina, a headless content management system. This vulnerability allows for potential data tampering or unauthorized access to sensitive data. The affected packages are next-tinacms-s3, next-tinacms-dos, next-tinacm [truncated]