THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-58fp-mcx6-7qf9 (medium) — Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets

[GHSA] GHSA-58fp-mcx6-7qf9 (medium) — Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets

highgithub_advisoriesPublished 2026-08-20

GHSA-58fp-mcx6-7qf9 Severity: medium CVE: CVE-2026-63179

Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets

### Impact

Affected versions of Winter CMS allow authenticated backend users with the following permissions to disclose arbitrary files readable by the PHP process by injecting `@import (inline) "<path>"` direct

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-58fp-mcx6-7qf9