๐Ÿ” CVE Alert

CVE-2026-69153

UNKNOWN 0.0

PostCSS: incomplete fix of CVE-2026-45623 โ€” attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting mapโ€™s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.

CWE CWE-22 CWE-200
Vendor postcss
Product postcss
Published Aug 3, 2026
Last Updated Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for postcss postcss

Be the first to know when new unknown vulnerabilities affecting postcss postcss are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

postcss / postcss
< 8.5.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp github.com: https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8 github.com: https://github.com/postcss/postcss/releases/tag/8.5.19