THREAT OPS › Threat News › [GHSA] GHSA-fxqj-rqcc-2cmp (medium) — PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset
[GHSA] GHSA-fxqj-rqcc-2cmp (medium) — PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset
GHSA-fxqj-rqcc-2cmp Severity: medium CVE: CVE-2026-69153
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset
## Summary
The fix for GHSA-6g55-p6wh-862q added a guard in `lib/previous-map.js` `PreviousMap.loadFile()` that restricts an attacker-controlled `sourceMappingURL` (from a CSS comment) to a `.map` extension
Indicators of compromise
- CVE-2026-69153cve
Original source: https://github.com/advisories/GHSA-fxqj-rqcc-2cmp