Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3888-q23f-x7qh | October CMS has Safe Mode Bypass via CSS Preprocessor Compilers |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Octobercms
Octobercms october |
|
| Vendors & Products |
Octobercms
Octobercms october |
Tue, 21 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a server-side information disclosure vulnerability was identified in the handling of CSS preprocessor files. Backend users with Editor permissions could craft .less, .sass, or .scss files that leverage the compiler's import functionality to read arbitrary files from the server. This worked even with cms.safe_mode enabled. This vulnerability is fixed in 3.7.14 and 4.1.10. | |
| Title | October: Safe Mode Bypass via CSS Preprocessor Compilers | |
| Weaknesses | CWE-184 CWE-863 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-21T17:35:19.882Z
Reserved: 2026-02-10T18:01:31.900Z
Link: CVE-2026-26067
Updated: 2026-04-21T17:35:13.271Z
Status : Received
Published: 2026-04-21T17:16:24.383
Modified: 2026-04-21T17:16:24.383
Link: CVE-2026-26067
No data.
OpenCVE Enrichment
Updated: 2026-04-22T03:15:06Z
Github GHSA