CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-69153

unknowncovered by 1 sourcefirst seen 2026-08-03
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.

⚡ Watch CVE-2026-69153

Get an email if CVE-2026-69153 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-69153

CVE.org record

Embed the live status

CVE-2026-69153 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-69153 status](https://www.csirts.com/badge/CVE-2026-69153)](https://www.csirts.com/cve/CVE-2026-69153)