CVE-2026-63179: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in wintercms winter
Description
Winter CMS versions up to and including 1.2.12 contain a path traversal vulnerability in the LESS compilation process. Authenticated backend users with certain permissions can inject @import directives into LESS source, allowing them to read arbitrary files accessible to the PHP process, including sensitive configuration files. The issue arises because the LESS parser does not enforce safe import path restrictions. This vulnerability is fixed in version 1.2.13.
CVSS v3.1
Score 4.9medium
Affected software
wintercms
winter
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-63179 is a path traversal vulnerability (CWE-22) in Winter CMS (winter) affecting versions up to 1.2.12. Authenticated backend users with permissions (such as those assigned to the Developer role) can inject @import (inline) directives into LESS source fields that the backend compiles without a safe import resolver. This allows the LESS parser to fall back to attacker-supplied paths, including absolute paths and directory traversal sequences, enabling disclosure of arbitrary files readable by the PHP process. Key sensitive files such as the application .env file containing APP_KEY and database credentials can be accessed. The flaw is reachable through multiple entry points including Brand Settings custom_css, Editor Settings html_custom_styles, Mail Brand Settings colour-picker fields, and theme .less, .sass, and .scss assets. The vulnerability is resolved in Winter CMS version 1.2.13.
Potential Impact
An attacker with authenticated backend access and appropriate permissions can read arbitrary files on the server that the PHP process can access. This includes sensitive configuration files such as the .env file, which may contain critical secrets like APP_KEY and database credentials. The vulnerability does not allow code execution or denial of service but leads to confidentiality loss of sensitive information.
Mitigation Recommendations
Upgrade Winter CMS to version 1.2.13 or later, where this vulnerability is fixed. Until then, restrict backend user permissions to trusted users only, especially those with the Developer role or equivalent permissions that allow LESS source injection. No other mitigations are documented.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-15T22:13:00.720Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a8f3604acd9273b49426232
Added to database: 08/26/2026, 18:52:52 UTC
Last enriched: 09/10/2026, 10:09:52 UTC
Last updated: 10/09/2026, 06:48:18 UTC
Views: 53
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.