Skip to main content
EPSS 0.5%top 58%

CVE-2026-63179: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in wintercms winter

0
Medium
VulnerabilityCVE-2026-63179cvecve-2026-63179cwe-22
Published: 08/26/2026 (08/26/2026, 18:06:14 UTC)
Source: CVE Database V5
Vendor/Project: wintercms
Product: winter

Description

Winter CMS versions up to and including 1.2.12 contain a path traversal vulnerability in the LESS compilation process. Authenticated backend users with certain permissions can inject @import directives into LESS source, allowing them to read arbitrary files accessible to the PHP process, including sensitive configuration files. The issue arises because the LESS parser does not enforce safe import path restrictions. This vulnerability is fixed in version 1.2.13.

CVSS v3.1

Score 4.9medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Affected software

wintercms

winter

Affected versions
<1.2.13

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 10:09:52 UTC

Technical Analysis

CVE-2026-63179 is a path traversal vulnerability (CWE-22) in Winter CMS (winter) affecting versions up to 1.2.12. Authenticated backend users with permissions (such as those assigned to the Developer role) can inject @import (inline) directives into LESS source fields that the backend compiles without a safe import resolver. This allows the LESS parser to fall back to attacker-supplied paths, including absolute paths and directory traversal sequences, enabling disclosure of arbitrary files readable by the PHP process. Key sensitive files such as the application .env file containing APP_KEY and database credentials can be accessed. The flaw is reachable through multiple entry points including Brand Settings custom_css, Editor Settings html_custom_styles, Mail Brand Settings colour-picker fields, and theme .less, .sass, and .scss assets. The vulnerability is resolved in Winter CMS version 1.2.13.

Potential Impact

An attacker with authenticated backend access and appropriate permissions can read arbitrary files on the server that the PHP process can access. This includes sensitive configuration files such as the .env file, which may contain critical secrets like APP_KEY and database credentials. The vulnerability does not allow code execution or denial of service but leads to confidentiality loss of sensitive information.

Mitigation Recommendations

Upgrade Winter CMS to version 1.2.13 or later, where this vulnerability is fixed. Until then, restrict backend user permissions to trusted users only, especially those with the Developer role or equivalent permissions that allow LESS source injection. No other mitigations are documented.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-07-15T22:13:00.720Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a8f3604acd9273b49426232

Added to database: 08/26/2026, 18:52:52 UTC

Last enriched: 09/10/2026, 10:09:52 UTC

Last updated: 10/09/2026, 06:48:18 UTC

Views: 53

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses