VDB
CVE-2026-69153
CVE-2026-69153
PUBLISHED
CVSS 6.3 MEDIUM
Reported by GitHub_M · Published August 3, 2026
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.
Risk Scores
CVSS 4.0
6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| postcss | postcss | < 8.5.19 |
| chainguard | cadence-web | 0, 0 |
| chainguard | authentik-2025.12 | 0, 0, 0 |
| chainguard | authentik-2026.2 | 0, 0, 0 |
| npm | postcss | 0 |
| wolfi | renovate | 0, 0, 0 |
| chainguard | keep | 0, 0, 0 |
| chainguard | vitess-23 | 0, 0 |
| chainguard | nextcloud-server-31 | 0, 0, 0 |
| chainguard | pelias-api | 0, 0, 0 |
| chainguard | nextcloud-server-33 | 0, 0 |
| wolfi | langfuse-3 | 0, 0, 0 |
| chainguard | semaphore | 0, 0, 0 |
| chainguard | langfuse-fips-3 | 0, 0 |
| chainguard | langfuse-3 | 0, 0 |
| chainguard | langfuse-fips-4 | 0, 0, 0 |
| wolfi | nextcloud-server-32 | 0, 0, 0 |
| chainguard | vitess-24 | 0, 0 |
| chainguard | arangodb-3.11 | 0 |
| postcss | postcss | < 8.5.19, < 8.5.19 |
…and 15 more
Timeline
- Aug 3, 2026 CVE Published
- Aug 3, 2026 Coalition ESS Score
- Aug 4, 2026 Security Advisory
- Aug 5, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
- Aug 13, 2026 Distribution Patch
- Aug 13, 2026 Security Advisory
- Aug 21, 2026 Distribution Patch
- Aug 21, 2026 Security Advisory
References
- https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp x_refsource_CONFIRM
- https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8 x_refsource_MISC
- https://github.com/postcss/postcss/releases/tag/8.5.19 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-69153 advisory
- https://github.com/advisories/GHSA-fxqj-rqcc-2cmp advisory