THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7mpf-4465-7fc2 (low) — Winter: Stored XSS through Backend List widget image columns

[GHSA] GHSA-7mpf-4465-7fc2 (low) — Winter: Stored XSS through Backend List widget image columns

highgithub_advisoriesPublished 2026-08-20

GHSA-7mpf-4465-7fc2 Severity: low CVE: None

Winter: Stored XSS through Backend List widget image columns

### Impact

`Backend\Widgets\Lists::evalImageTypeValue()` interpolated the resolved image URL into a single-quoted `src` attribute without escaping it. Where a list column of type `image` rendered an attacker-influenced value, that v

Indicators of compromise

Original source: https://github.com/advisories/GHSA-7mpf-4465-7fc2