Vulnerability GHSA-5hxf-c7j4-279c
Summary
Tina: Path Traversal in Media Upload Handle
Details
Affected Package
| Field | Value |
|---|---|
| Package | @tinacms/cli |
| Version | 2.0.5 (latest at time of discovery) |
| Vulnerable File | packages/@tinacms/cli/src/next/commands/dev-command/server/media.ts |
| Vulnerable Lines | 42-43 |
Details
Vulnerable Code Location
File: packages/@tinacms/cli/src/next/commands/dev-command/server/media.ts
Lines: 42-43
bb.on('file', async (_name, file, _info) => {
const fullPath = decodeURI(req.url?.slice('/media/upload/'.length)); // Line 42
const saveTo = path.join(mediaFolder, ...fullPath.split('/')); // Line 43
// make sure the directory exists before writing the file
await fs.ensureDir(path.dirname(saveTo));
file.pipe(fs.createWriteStream(saveTo));
});
Root Cause
The path.join() function resolves .. (parent directory) segments in the path. When the user-supplied path contains traversal sequences like ../../../etc/passwd, these are resolved relative to the media folder, allowing escape to arbitrary filesystem locations.
Example:
const mediaFolder = '/app/public/uploads';
const maliciousInput = '../../../tmp/evil.txt';
const saveTo = path.join(mediaFolder, ...maliciousInput.split('/'));
// Result: '/tmp/evil.txt' - OUTSIDE the media folder!
Additional Affected Endpoints
The same vulnerability pattern exists in:
- Delete Handler (
handleDelete, lines 29-33) - Arbitrary file deletion - List Handler (
handleList, lines 16-27) +MediaModel.listMedia- Directory enumeration - MediaModel.deleteMedia (lines 201-217) - Arbitrary file deletion
Similar code also exists in the Express version at:
packages/@tinacms/cli/src/server/routes/index.tspackages/@tinacms/cli/src/server/models/media.ts
Evidence That Path Traversal Should Be Blocked
Your codebase already shows that path traversal is considered a security issue:
// From: packages/@tinacms/graphql/tests/pending-document-validation/index.test.ts:52-70
it('handles validation error for invalid path format', async () => {
const { query } = await setupMutation(__dirname, config);
const invalidPathMutation = `
mutation {
addPendingDocument(
collection: "post"
relativePath: "../invalid-path.md" // <-- Path traversal is rejected!
) {
__typename
}
}
`;
const result = await query({ query: invalidPathMutation, variables: {} });
expect(result.errors).toBeDefined();
expect(result.errors?.length).toBeGreaterThan(0);
});
This test explicitly verifies that ../invalid-path.md is rejected in the GraphQL layer. The media upload endpoints should have the same protection.
Recommended Fix
Add path validation to ensure the resolved path stays within the media directory:
import path from 'path';
const handlePost = async function (req, res) {
const bb = busboy({ headers: req.headers });
bb.on('file', async (_name, file, _info) => {
const fullPath = decodeURI(req.url?.slice('/media/upload/'.length));
const saveTo = path.join(mediaFolder, ...fullPath.split('/'));
// ✅ SECURITY FIX: Validate path stays within media folder
const resolvedPath = path.resolve(saveTo);
const resolvedMediaFolder = path.resolve(mediaFolder);
if (!resolvedPath.startsWith(resolvedMediaFolder + path.sep)) {
res.statusCode = 403;
res.end(JSON.stringify({ error: 'Invalid file path' }));
return;
}
await fs.ensureDir(path.dirname(saveTo));
file.pipe(fs.createWriteStream(saveTo));
});
// ... rest of handler
};
The same fix should be applied to:
handleDeletefunctionhandleListfunctionMediaModel.listMediamethodMediaModel.deleteMediamethod- Express router in
packages/@tinacms/cli/src/server/
Alternative: Create a Validation Helper
function validateMediaPath(userPath: string, mediaFolder: string): string {
const resolved = path.resolve(path.join(mediaFolder, ...userPath.split('/')));
const resolvedBase = path.resolve(mediaFolder);
if (!resolved.startsWith(resolvedBase + path.sep) && resolved !== resolvedBase) {
throw new Error('Path traversal detected');
}
return resolved;
}
Related Vulnerabilities
Other vulnerabilities affecting the same packages