Executive brief
Winter CMS is a content management system that allows administrators to edit template code. A flaw in the template sandbox (a security layer meant to restrict dangerous operations) allows authenticated editors to bypass restrictions and gain unauthorized database access, modify data, and execute arbitrary code on the server. This affects users with template-editing permissions.
Technical details
This is an incomplete fix for CVE-2024-54149 affecting Winter CMS versions 1.2.7–1.2.12. The Twig sandbox escape vulnerability exists in System\Twig\SecurityPolicy due to a flawed method blocklist that does not account for Eloquent model __call forwarding to the query builder. An authenticated backend user with cms.manage_pages, cms.manage_layouts, or cms.manage_partials permissions can bypass sandbox restrictions via forwarded methods (saveQuietly(), deleteQuietly(), increment(), decrement(), newQuery()) and higher-order collection methods that accept callables. Exploitation requires an existing backend account with template-editing permissions; no network authentication is needed beyond that. An attacker can read/modify arbitrary database records, execute raw SQL, exfiltrate credentials, and inject PHP into page/layout/partial code sections for RCE. The fix (v1.2.13) reworks SecurityPolicy with a transitive forwarder chain blocklist, expanded per-class restrictions, connection lockdown, and SafeCollection/SafePaginator proxies to neutralize callable arguments.
Affected products
- Winter CMS Winter 1.2.7 to 1.2.12
Timeline
- 2026-08-07: disclosed
- 2026-07-25: patched: Patch commit 725bbcda merged
- 2026-08-25: advisory: CVE-2026-79774 published