Description
File: lib/previous-map.js Line: 87-98 (loadFile), 129-144 (loadMap)
Recommendation
Update the postcss package to the latest compatible version. Followings are version details:
- Affected version(s): <= 8.5.17
- Patched version(s): 8.5.18
References
Could your website be exposed too?
SmartScanner can check your website for PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure and gives you actionable findings to investigate.
Start a free scanRelated Issues
- PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments - CVE-2026-45623
- PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `f - CVE-2026-69153
- Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read - CVE-2026-40163
- @tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files - CVE-2026-33949
You might also like:
See something that needs correcting? Let us knowUpdated August 13, 2026


