MODERATEnpm

PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset

PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset

CVE-2026-69153Published 2 days agoUpdated 1 day agoSource: OSV

Affected packages

  • postcss

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.36%
EPSS percentile
28.5%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 28%.

PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset | HackTribune