THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8cfw-pcwh-v63w (high) — Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)

[GHSA] GHSA-8cfw-pcwh-v63w (high) — Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)

highgithub_advisoriesPublished 2026-08-20

GHSA-8cfw-pcwh-v63w Severity: high CVE: None

Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)

### Impact

Affected versions of Winter CMS allow authenticated backend users with CMS template-editing permissions to escape the Twig sandbox ("safe mode") that is meant to restrict what template code can do. Using any of the following permissions, an attacker

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8cfw-pcwh-v63w