Medium severity5.3NVD Advisory· Published Sep 29, 2023· Updated Jun 17, 2026
CVE-2023-44270
CVE-2023-44270
Description
An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being included in a comment.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
postcssnpm | < 8.4.31 | 8.4.31 |
Affected products
7- osv-coords6 versionspkg:apk/chainguard/py3.10-captumpkg:apk/chainguard/py3.11-captumpkg:apk/chainguard/py3.12-captumpkg:apk/chainguard/py3.13-captumpkg:npm/postcsspkg:rpm/opensuse/velociraptor&distro=openSUSE%20Tumbleweed
< 0.9.0-r1+ 5 more
- (no CPE)range: < 0.9.0-r1
- (no CPE)range: < 0.9.0-r1
- (no CPE)range: < 0.9.0-r1
- (no CPE)range: < 0.9.0-r1
- (no CPE)range: < 8.4.31
- (no CPE)range: < 0.7.0.4.git142.862ef23-1.1
Patches
Vulnerability mechanics
References
7- github.com/postcss/postcss/commit/58cc860b4c1707510c9cd1bc1fa30b423a9ad6c5nvdPatchWEB
- github.com/postcss/postcss/releases/tag/8.4.31nvdPatchRelease NotesWEB
- github.com/advisories/GHSA-7fh5-64p2-3v2jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-44270ghsaADVISORY
- github.com/github/advisory-database/issues/2820nvdIssue TrackingWEB
- github.com/postcss/postcss/blob/main/lib/tokenize.jsnvdIssue TrackingWEB
- lists.debian.org/debian-lts-announce/2024/12/msg00025.htmlnvdWEB
News mentions
0No linked articles in our index yet.