Vulnerabilities
1 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-45623 | Path Traversal Arbitrary File Read in PostCSS PreviousMap Processing PostCSS 8.5.11 and earlier mishandle the /*# sourceMappingURL=PATH */ comment: the PreviousMap code dereferences PATH against the local filesystem with no scheme restriction, allowlist, or traversal check when processing any CSS string. An attacker who controls the CSS input, such as a user-uploaded stylesheet, CMS theme, userstyle, or blog-comment renderer content, can make the host Node process read any file readable by it and leak roughly the first 10 bytes of the content through a JSON.parse SyntaxError message, while also gaining a precise file-existence oracle and a controllable-read primitive that can be combined with large-file targets for denial of service. The behavior triggers with PostCSS's default options (no 'from', no 'map', no plugins required), so any pipeline that runs untrusted CSS through PostCSS at runtime is affected. All consumers of PostCSS 8.5.11 and prior are affected; build pipelines handling only trusted, first-party CSS are far less exposed. Exploitation has not been confirmed in the wild (EPSS ~0.6%, not in CISA KEV), but a public advisory with a PoC reference exists. Do: Upgrade to PostCSS 8.5.12 or later, and audit your dependency tree (npm ls postcss / lockfiles) since PostCSS is commonly pulled in transitively by build tooling. Where PostCSS runs on untrusted CSS at runtime (CMS themes, uploaded styles, userstyle processors), strip or sanitize sourceMappingURL comments as an interim mitigation until patched. No in-the-wild exploitation is known; patching build-time-only use of trusted CSS is lower priority. | 9.1 | <1% | PoC |
| mass>1M deployments (tens of millions of weekly npm downloads); directly exposed runtime consumers plausibly 100k+ |