THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fxqj-rqcc-2cmp (medium) — PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset

[GHSA] GHSA-fxqj-rqcc-2cmp (medium) — PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset

medgithub_advisoriesPublished 2026-08-03

GHSA-fxqj-rqcc-2cmp Severity: medium CVE: CVE-2026-69153

PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset

## Summary

The fix for GHSA-6g55-p6wh-862q added a guard in `lib/previous-map.js` `PreviousMap.loadFile()` that restricts an attacker-controlled `sourceMappingURL` (from a CSS comment) to a `.map` extension

Indicators of compromise

Original source: https://github.com/advisories/GHSA-fxqj-rqcc-2cmp