October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a server-side information disclosure vulnerability was identified in the handling of CSS preprocessor files. Backend users with Editor permissions could craft .less, .sass, or .scss files that leverage the compiler's import functionality to read arbitrary files from the server. This worked even with cms.safe_mode enabled. This vulnerability is fixed in 3.7.14 and 4.1.10.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3888-q23f-x7qh | October CMS has Safe Mode Bypass via CSS Preprocessor Compilers |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 21 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Octobercms
Octobercms october |
|
| Vendors & Products |
Octobercms
Octobercms october |
Tue, 21 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a server-side information disclosure vulnerability was identified in the handling of CSS preprocessor files. Backend users with Editor permissions could craft .less, .sass, or .scss files that leverage the compiler's import functionality to read arbitrary files from the server. This worked even with cms.safe_mode enabled. This vulnerability is fixed in 3.7.14 and 4.1.10. | |
| Title | October: Safe Mode Bypass via CSS Preprocessor Compilers | |
| Weaknesses | CWE-184 CWE-863 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-21T17:35:19.882Z
Reserved: 2026-02-10T18:01:31.900Z
Link: CVE-2026-26067
No data.
Status : Received
Published: 2026-04-21T17:16:24.383
Modified: 2026-04-21T17:16:24.383
Link: CVE-2026-26067
No data.
OpenCVE Enrichment
Updated: 2026-04-21T17:30:37Z
Github GHSA