THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-v7cf-8gh9-gxmj (high) — Winter: Stored XSS through Brand Settings custom styles

[GHSA] GHSA-v7cf-8gh9-gxmj (high) — Winter: Stored XSS through Brand Settings custom styles

highgithub_advisoriesPublished 2026-08-12

GHSA-v7cf-8gh9-gxmj Severity: high CVE: CVE-2026-32257

Winter: Stored XSS through Brand Settings custom styles

### Impact

Users with the `backend.manage_branding` ("Customize the back-end") permission can provide custom CSS through **Settings → Customize Backend → Styles** that is compiled thr

Indicators of compromise

Original source: https://github.com/advisories/GHSA-v7cf-8gh9-gxmj