SCA: security update for winter/wn-system-module (GHSA-8cfw-pcwh-v63w)

high Tenable Self-Hosted Container Security Plugin ID 446184

Description

Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)

Solution

Update the winter/wn-system-module library and its related packages to version 1.2.13 or later.

See Also

https://github.com/advisories/GHSA-8cfw-pcwh-v63w

Plugin Details

Severity: High

ID: 446184

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/21/2026

Updated: 8/21/2026

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/20/2026

Vulnerability Publication Date: 8/20/2026

Reference Information

cwe: CWE-693