FlareStart
HomeNewsHow ToSources
FlareStart

Where developers start their day. All the tech news & tutorials that matter, in one place.

Quick Links

  • Home
  • News
  • Tutorials
  • Sources
  • Privacy Policy

Connect

© 2026 FlareStart. All rights reserved.

Back to articles
CVE-2026-29066: CVE-2026-29066: Arbitrary File Read in TinaCMS CLI via Permissive Vite Configuration
NewsSecurity

CVE-2026-29066: CVE-2026-29066: Arbitrary File Read in TinaCMS CLI via Permissive Vite Configuration

via Dev.toCVE Reports2w ago

CVE-2026-29066: Arbitrary File Read in TinaCMS CLI via Permissive Vite Configuration Vulnerability ID: CVE-2026-29066 CVSS Score: 6.2 Published: 2026-03-12 The @tinacms/cli package prior to version 2.1.8 contains a medium-severity vulnerability that allows unauthenticated local or adjacent attackers to read arbitrary files from the host filesystem. This occurs due to an insecure Vite development server configuration that explicitly disables filesystem strict boundaries. TL;DR TinaCMS CLI versions prior to 2.1.8 explicitly disable Vite's strict filesystem checks, enabling an unauthenticated arbitrary file read vulnerability via the development server's / @fs / endpoint. ⚠️ Exploit Status: POC Technical Details CWE ID : CWE-552 / CWE-200 Attack Vector : Local / Adjacent Network CVSS Score : 6.2 Impact : High Confidentiality (Arbitrary File Read) Exploit Status : Proof of Concept (PoC) Available KEV Status : Not Listed Affected Systems TinaCMS CLI (< 2.1.8) Vite Development Server (Embedd

Continue reading on Dev.to

Opens in a new tab

Read Full Article
19 views

Related Articles

These car gadgets are worth every penny
News

These car gadgets are worth every penny

ZDNet • 3h ago

These Are the 4 Artemis II Astronauts Leading the Historic Return to the Moon
News

These Are the 4 Artemis II Astronauts Leading the Historic Return to the Moon

Wired • 3h ago

Taylor Lorenz’s Screen Time Is Almost 17 Hours a Day
News

Taylor Lorenz’s Screen Time Is Almost 17 Hours a Day

Wired • 3h ago

RSpec Best Practices in 2026: Factory Bot + VCR Cassettes
News

RSpec Best Practices in 2026: Factory Bot + VCR Cassettes

Medium Programming • 4h ago

The $380K Outage — Complete Timeline From Hell (2:14 AM to 4:02 AM)
News

The $380K Outage — Complete Timeline From Hell (2:14 AM to 4:02 AM)

Medium Programming • 4h ago

Discover More Articles