THREAT OPS › Threat News › [GHSA] GHSA-v7cf-8gh9-gxmj (high) — Winter: Stored XSS through Brand Settings custom styles
[GHSA] GHSA-v7cf-8gh9-gxmj (high) — Winter: Stored XSS through Brand Settings custom styles
GHSA-v7cf-8gh9-gxmj Severity: high CVE: CVE-2026-32257
Winter: Stored XSS through Brand Settings custom styles
### Impact
Users with the `backend.manage_branding` ("Customize the back-end") permission can provide custom CSS through **Settings → Customize Backend → Styles** that is compiled thr
Indicators of compromise
- d28f0b9474af79cfaa80eeb9d691f7a7c4469720sha1
- CVE-2026-32257cve
- CVE-2025-61676cve
Original source: https://github.com/advisories/GHSA-v7cf-8gh9-gxmj