CVE-2026-69153: PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-69153
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-69153 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for PostCSS takes a
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
More from NVD Recent CVEs
- highCVE-2026-69152: The brace-expansion library generates arbitrary strings containing a common prefix and suffix.…2026-08-03
- unknownCVE-2026-69151: Angular is a development platform for building mobile and desktop web applications using TypeS…2026-08-03
- unknownCVE-2026-69149: Angular is a development platform for building mobile and desktop web applications using TypeS…2026-08-03
- unknownCVE-2026-68945: Angular is a development platform for building mobile and desktop web applications using TypeS…2026-08-03
- mediumCVE-2026-68930: Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped …2026-08-03