{"apiVersion":"1.0","identifier":"CVE-2026-63179","description":"Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, authenticated backend users can disclose arbitrary files readable by the PHP process by injecting @import (inline) directives into LESS source that the backend compiles, because the LESS parser was instantiated without a safe import resolver and fell back to the raw attacker-supplied path when no allowed root matched. The flaw is reachable through four entry points that share the same root cause: the Brand Settings custom_css field, the Editor Settings html_custom_styles field, the Mail Brand Settings colour-picker fields whose values are concatenated into LESS source without escaping, and theme .less, .sass, and .scss assets compiled when served. Both absolute paths and .. traversal outside the asset-s own tree were accepted, so an attacker could read any file the web process can access, most significantly the application .env file and the APP_KEY and database credentials it contains. Exploitation requires a backend account holding one of the associated permissions, which are assigned by default to the built-in Developer role. This issue is fixed in version 1.2.13.","publishedAt":"2026-08-26T19:16:51","lastModifiedAt":"2026-08-26T20:17:56","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63179","cvssScore":4.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","epssProbability":0.00351,"riskScore":0.51,"affectedProduct":"Winter CMS","affectedVersions":"<=1.2.12","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-63179","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-63179","en":"https://www.redsauce.net/en/cves/CVE-2026-63179","fr":"https://www.redsauce.net/fr/cves/CVE-2026-63179","pt":"https://www.redsauce.net/pt/cves/CVE-2026-63179","de":"https://www.redsauce.net/de/cves/CVE-2026-63179","sk":"https://www.redsauce.net/sk/cves/CVE-2026-63179","el":"https://www.redsauce.net/el/cves/CVE-2026-63179"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-63179"}}