Aller au contenu

Fiche vulnérabilité

CVE-2026-69153 : faille moyenne postcss postcss (CVSS 5.3)

Description

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.

En bref

Sévérité
Moyenne (CVSS 5.3)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
3 août 2026
Dernière mise à jour
5 août 2026

Produits concernés

  • postcss postcss

Références

Rechercher une autre vulnérabilité dans la base CVE