A AegiFlow
MEDIUMCVSS 6.3EPSS 0.5%

CVE-2026-69153

CVE-2026-69153 updated by NVD

Published
2026-08-03
Modified
2026-09-21
EPSS percentile
39%
Sources
github-advisory, nvd, osv

Summary

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmpostcss8.5.23
npmpostcss8.5.23

Remediation: Upgrade to 8.5.23 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

Includes data from OSV.dev.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.