Description
An issue was discovered in PostCSS before 8.4.31. It affects linters using PostCSS to parse external Cascading Style Sheets (CSS). There may be \r discrepancies, as demonstrated by @font-face{ font:(\r/*);} in a rule.
This vulnerability affects linters using PostCSS to parse external untrusted CSS.
Recommendation
Update the postcss package to the latest compatible version. Followings are version details:
- Affected version(s): < 8.4.31
- Patched version(s): 8.4.31
References
Related Issues
- Uncaught Exception in yaml - CVE-2023-2251
- Joplin Cross-site Scripting vulnerability - joplin - CVE-2023-37298
- Joplin Cross-site Scripting vulnerability - CVE-2023-37299
- protobufjs Prototype Pollution vulnerability - CVE-2023-36665
You might also like:
- Tags:
- npm
- postcss
Anything's wrong? Let us know Last updated on November 04, 2025


