CVE-2026-69153
PostCSS: incomplete fix of CVE-2026-45623 โ attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting mapโs sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.
| CWE | CWE-22 CWE-200 |
| Vendor | postcss |
| Product | postcss |
| Published | Aug 3, 2026 |
| Last Updated | Aug 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for postcss postcss
Be the first to know when new unknown vulnerabilities affecting postcss postcss are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
postcss / postcss
< 8.5.19