PT-2026-81362 · Unknown · Winter Cms

·

CVE-2026-79773

·

Published

2026-08-20

·

Updated

2026-08-25

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Winter CMS versions prior to 1.2.13
Description A local file inclusion issue exists in the JavascriptImporter filter. Authenticated users with cms.manage assets permission can disclose arbitrary server-readable files, such as the .env file located outside the theme directory, by inserting =include or =require directives into theme JavaScript assets. The combined output is then served through the combine route, making sensitive information like application keys and database credentials accessible to unauthenticated visitors.
Recommendations Update Winter CMS to version 1.2.13 or later.

Exploit

Fix

Path traversal

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79773
GHSA-2223-F22X-24CQ

Affected Products

Winter Cms