THREAT OPS › Threat News › [GHSA] GHSA-58fp-mcx6-7qf9 (medium) — Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets
[GHSA] GHSA-58fp-mcx6-7qf9 (medium) — Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets
GHSA-58fp-mcx6-7qf9 Severity: medium CVE: CVE-2026-63179
Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets
### Impact
Affected versions of Winter CMS allow authenticated backend users with the following permissions to disclose arbitrary files readable by the PHP process by injecting `@import (inline) "<path>"` direct
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- 130f0ea43e9228bf0d129b481da1cdfbcc4b4456sha1
- af770331c683e628533a6ec2991285d6e10a4d6csha1
- CVE-2026-63179cve
- hello@wintercms.comemail
Original source: https://github.com/advisories/GHSA-58fp-mcx6-7qf9