CVE-2026-24125: Tinacms Media Path Traversal
A path traversal vulnerability occurs when user-controlled input is concatenated using `path.join()` without validating that it resolves within the intended root directory. Using this path in file system functions permits an attacker to perform unauthorized file read, write, or deletion outside the application's bounds.
greprules fetch cve-2026-24125-tinacms-media-path-traversal --engine opengrepDescription
A path traversal vulnerability occurs when user-controlled input is concatenated using `path.join()` without validating that it resolves within the intended root directory. Using this path in file system functions permits an attacker to perform unauthorized file read, write, or deletion outside the application's bounds.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.