Executive brief
Winter CMS is a content management system that manages website themes and assets. Authenticated users with asset management permissions can inject directives into JavaScript files that cause the system to include arbitrary server files (like .env configuration files) in the output. This exposed data is then served to any visitor of the website, leaking sensitive credentials and application keys.
Technical details
Winter CMS before version 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter component. The vulnerability exists because the filter does not properly validate or restrict file paths when processing =include or =require directives in JavaScript assets, allowing directory traversal attacks. Authenticated users with the cms.manage_assets permission can place malicious directives in theme JavaScript files to reference files outside the theme directory (such as .env). The combined asset output served through the combine route is accessible to unauthenticated visitors, exposing sensitive files containing database credentials and application keys. Fixes have been applied via commits to confine JavaScript importer paths to allowed directory roots.
Affected products
- Winter CMS Winter CMS before 1.2.13
Timeline
- 2026-08-25: disclosed
- 2026-08-06: patched