<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 06:48:55 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-275987</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275987</link>
      <description>EUVD-2026-275987</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275987</guid>
    </item>
    <item>
      <title>fkie_cve-2026-29066</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-29066</link>
      <description>&lt;p&gt;Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite&amp;#39;s built-in filesystem access restriction. This allows any unauthenticated attacker who can reach the dev server to read arbitrary files on the host system. This vulnerability is fixed in 2.1.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite&amp;#39;s built-in filesystem access restriction. This allows any unauthenticated attacker who can reach the dev server to read arbitrary files on the host system. This vulnerability is fixed in 2.1.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-29066</guid>
    </item>
    <item>
      <title>GHSA-m48g-4wr2-j2h6 — TinaCMS CLI has Arbitrary File Read via Disabled Vite Filesystem Restriction</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m48g-4wr2-j2h6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @tinacms/cli&lt;/p&gt;
&lt;p&gt;## Summary
The TinaCMS CLI dev server configures Vite with `server.fs.strict: false`, which disables Vite&amp;#39;s built-in filesystem access restriction. This allows any unauthenticated attacker who can reach the dev server to read arbitrary files on the host system&lt;/p&gt;
&lt;p&gt;## Details
When running `tinacms dev`, the CLI starts a Vite dev server configured in:
`packages/@tinacms/cli/src/next/vite/index.ts`
```
server: {
  host: configManager.config?.build?.host ?? false,
  ...
  fs: {
    strict: false, // Disables Vite&amp;#39;s filesystem access restriction
  },
},
```
TinaCMS middleware only intercepts specific route prefixes (/media/*, /graphql, /altair, /searchIndex). Any request to a path outside these routes falls through to Vite&amp;#39;s default static file handler, which will serve the file directly from the absolute path on the filesystem.
Additionally, the server enables permissive CORS (cors() with no origin restriction), which may further facilitate browser-based exploitation such as DNS rebinding attacks.&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;**Prerequisites**: TinaCMS CLI dev server running (default port 4001).&lt;/p&gt;
&lt;p&gt;- Read system files directly:
```
curl http://localhost:4001/etc/passwd
```
&amp;lt;img width=&amp;#34;705&amp;#34; height=&amp;#34;332&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/6fd0e1c7-a549-40c8-bc81-af9c343f52a0&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;```
curl http://localhost:4001/etc/hostname
```
&amp;lt;img width=&amp;#34;631&amp;#34; height=&amp;#34;41&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/bd103dc3-d4c3-4774-8007-b55de3fc2a9e&amp;#34; /&amp;gt;
Vite resolves and serves t…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @tinacms/cli&lt;/p&gt;
&lt;p&gt;## Summary
The TinaCMS CLI dev server configures Vite with `server.fs.strict: false`, which disables Vite&amp;#39;s built-in filesystem access restriction. This allows any unauthenticated attacker who can reach the dev server to read arbitrary files on the host system&lt;/p&gt;
&lt;p&gt;## Details
When running `tinacms dev`, the CLI starts a Vite dev server configured in:
`packages/@tinacms/cli/src/next/vite/index.ts`
```
server: {
  host: configManager.config?.build?.host ?? false,
  ...
  fs: {
    strict: false, // Disables Vite&amp;#39;s filesystem access restriction
  },
},
```
TinaCMS middleware only intercepts specific route prefixes (/media/*, /graphql, /altair, /searchIndex). Any request to a path outside these routes falls through to Vite&amp;#39;s default static file handler, which will serve the file directly from the absolute path on the filesystem.
Additionally, the server enables permissive CORS (cors() with no origin restriction), which may further facilitate browser-based exploitation such as DNS rebinding attacks.&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;**Prerequisites**: TinaCMS CLI dev server running (default port 4001).&lt;/p&gt;
&lt;p&gt;- Read system files directly:
```
curl http://localhost:4001/etc/passwd
```
&amp;lt;img width=&amp;#34;705&amp;#34; height=&amp;#34;332&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/6fd0e1c7-a549-40c8-bc81-af9c343f52a0&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;```
curl http://localhost:4001/etc/hostname
```
&amp;lt;img width=&amp;#34;631&amp;#34; height=&amp;#34;41&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/bd103dc3-d4c3-4774-8007-b55de3fc2a9e&amp;#34; /&amp;gt;
Vite resolves and serves t…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m48g-4wr2-j2h6</guid>
    </item>
  </channel>
</rss>
