CVE-2026-63123 is a medium-severity vulnerability affecting @tinacms/cli versions < 2.5.2 in the Tina dev server with a CVSS score of 6.5, allowing an attacker-controlled website to cause arbitrary file creation inside the configured media upload directory on a developer machine running `tinacms dev` via cross-origin `POST` requests. This flaw enables an attacker to write files with arbitrary contents into the media root without requiring manual file upload, resulting in integrity impact on local project files under the upload root. The vulnerability is exploitable because `multipart/form-data` is a simple browser request and does not require a preflight, allowing CORS to only prevent the attacking page from reading the response while still permitting the local Tina server to process the state-changing request.
We recommend you to update @tinacms/cli to version 2.5.2.[/subscribe_to_unlock_form]
CVE-2026-63123 is a medium-severity vulnerability affecting @tinacms/cli versions < 2.5.2 in the Tina dev server with a CVSS score of 6.5, allowing an attacker-controlled website to cause arbitrary file creation inside the configured media upload directory on a developer machine running `tinacms dev` via cross-origin `POST` requests. This flaw enables an attacker to write files with arbitrary contents into the media root without requiring manual file upload, resulting in integrity impact on local project files under the upload root. The vulnerability is exploitable because `multipart/form-data` is a simple browser request and does not require a preflight, allowing CORS to only prevent the attacking page from reading the response while still permitting the local Tina server to process the state-changing request.
We recommend you to update @tinacms/cli to version 2.5.2.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]