VDB

CVE-2026-69153

CVE-2026-69153 PUBLISHED CVSS 6.3 MEDIUM

Reported by GitHub_M · Published August 3, 2026

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.

Risk Scores

CVSS 4.0
6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
postcsspostcss< 8.5.19
chainguardcadence-web0, 0
chainguardauthentik-2025.120, 0, 0
chainguardauthentik-2026.20, 0, 0
npmpostcss0
wolfirenovate0, 0, 0
chainguardkeep0, 0, 0
chainguardvitess-230, 0
chainguardnextcloud-server-310, 0, 0
chainguardpelias-api0, 0, 0
chainguardnextcloud-server-330, 0
wolfilangfuse-30, 0, 0
chainguardsemaphore0, 0, 0
chainguardlangfuse-fips-30, 0
chainguardlangfuse-30, 0
chainguardlangfuse-fips-40, 0, 0
wolfinextcloud-server-320, 0, 0
chainguardvitess-240, 0
chainguardarangodb-3.110
postcsspostcss< 8.5.19, < 8.5.19

…and 15 more

Timeline

  • Aug 3, 2026 CVE Published
  • Aug 3, 2026 Coalition ESS Score
  • Aug 4, 2026 Security Advisory
  • Aug 5, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score
  • Aug 13, 2026 Distribution Patch
  • Aug 13, 2026 Security Advisory
  • Aug 21, 2026 Distribution Patch
  • Aug 21, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›