VYPR
High severity7.5NVD Advisory· Published Aug 17, 2026· Updated Sep 18, 2026

CVE-2026-73646

CVE-2026-73646

Description

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values to join(dirname(opts.from), annotation), and loadFile() permits traversed or absolute .map paths, allowing untrusted CSS processed without map: false to disclose sourcesContent from arbitrary reachable .map files through result.map. This issue is fixed in version 8.5.18.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
postcssnpm
< 8.5.188.5.18

Affected products

34

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.