CVE-2026-34603 — Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal checks to the dev media routes, but the implementation still validates only the — CVE Database · The Intelligence Room