CVE-2026-69153

NameCVE-2026-69153
DescriptionPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-postcss (PTS)bullseye8.2.1+~cs5.3.23-8vulnerable
bullseye (security)8.2.1+~cs5.3.23-8+deb11u1vulnerable
bookworm8.4.20+~cs8.0.23-1+deb12u1vulnerable
trixie8.4.49+~cs9.2.32-1vulnerable
forky, sid8.5.26+~cs10.2.24-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-postcsssource(unstable)8.5.23+~cs10.2.23-1

Notes

[trixie] - node-postcss <no-dsa> (Minor issue)
https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp
Fixed by: https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8 (8.5.23)

Search for package or bug name: Reporting problems