<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T01:41:22.962656+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-275987</id>
    <title>EUVD-2026-275987</title>
    <updated>2026-10-07T01:41:23.009299+00:00</updated>
    <content>EUVD-2026-275987</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-275987"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-29066</id>
    <title>fkie_cve-2026-29066</title>
    <updated>2026-10-07T01:41:23.009337+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite's built-in filesystem access restriction. This allows any unauthenticated attacker who can reach the dev server to read arbitrary files on the host system. This vulnerability is fixed in 2.1.8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-29066"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m48g-4wr2-j2h6</id>
    <title>GHSA-m48g-4wr2-j2h6 — TinaCMS CLI has Arbitrary File Read via Disabled Vite Filesystem Restriction</title>
    <updated>2026-10-07T01:41:23.009372+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @tinacms/cli</p>
<p>## Summary
The TinaCMS CLI dev server configures Vite with `server.fs.strict: false`, which disables Vite's built-in filesystem access restriction. This allows any unauthenticated attacker who can reach the dev server to read arbitrary files on the host system</p>
<p>## Details
When running `tinacms dev`, the CLI starts a Vite dev server configured in:
`packages/@tinacms/cli/src/next/vite/index.ts`
```
server: {
  host: configManager.config?.build?.host ?? false,
  ...
  fs: {
    strict: false, // Disables Vite's filesystem access restriction
  },
},
```
TinaCMS middleware only intercepts specific route prefixes (/media/*, /graphql, /altair, /searchIndex). Any request to a path outside these routes falls through to Vite's default static file handler, which will serve the file directly from the absolute path on the filesystem.
Additionally, the server enables permissive CORS (cors() with no origin restriction), which may further facilitate browser-based exploitation such as DNS rebinding attacks.</p>
<p>## PoC</p>
<p>**Prerequisites**: TinaCMS CLI dev server running (default port 4001).</p>
<p>- Read system files directly:
```
curl http://localhost:4001/etc/passwd
```
&lt;img width="705" height="332" alt="image" src="https://github.com/user-attachments/assets/6fd0e1c7-a549-40c8-bc81-af9c343f52a0" /&gt;</p>
<p>```
curl http://localhost:4001/etc/hostname
```
&lt;img width="631" height="41" alt="image" src="https://github.com/user-attachments/assets/bd103dc3-d4c3-4774-8007-b55de3fc2a9e" /&gt;
Vite resolves and serves t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m48g-4wr2-j2h6"/>
  </entry>
</feed>
