CVE-2026-79773: Winter CMS before 1.2.13 Local File Inclusion via JavaScript

Published Aug 25, 2026
·
Updated

Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows authenticated users with cms.manageassets permission to disclose arbitrary server-readable files by placing =include or =require directives in theme JavaScript assets. Attackers can reference files like .env outside the theme directory, and the combined output served through the combine route becomes readable by unauthenticated visitors, exposing application keys and database credentials.

Affected Software

1 affected component
Winter CMS<1.2.13

Event History

Aug 25, 2026
CVE Published
via MITRE·03:16 PM
Data Sourced
via MITRE·03:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Apr 30, 58619
Event
via NVD·01:59 AM

Frequently Asked Questions

1

Who can exploit this vulnerability?

An authenticated Winter CMS user with the cms.manage_assets permission can exploit it. The disclosed content can then be retrieved by unauthenticated visitors through the combine route.

2

What access and conditions are required for exploitation?

The attacker needs an account with cms.manage_assets permission and the ability to place =include or =require directives in a theme JavaScript asset. They can use those directives to reference server-readable files outside the theme directory.

3

What is the impact if exploitation succeeds?

An attacker can disclose arbitrary files that the server process can read, including files such as .env. Exposed data may include application keys and database credentials.

4

How can defenders identify possible exploitation?

Review theme JavaScript assets for =include or =require directives, particularly directives referencing paths outside the theme directory. Also assess whether combined JavaScript output available through the combine route contains unexpected file content or sensitive configuration values.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203